Trust Center

Security is Architecture, Not a Feature.

Every layer of ShadowTagAI is built for zero-trust data sovereignty. From encryption at rest to tenant isolation β€” security is structural, not bolted on.

Compliance

Certifications & Standards

πŸ›‘οΈ

SOC 2 Type II

Annual audit covering security, availability, and confidentiality trust service criteria. No Type II report is published here.

Not certified
πŸ‡ͺπŸ‡Ί

GDPR Art. 28

Data Processing Agreements may be offered for international deployments. This is not a certification badge.

Not a certification
πŸ₯

HIPAA

BAA-ready design is not a blanket HIPAA certification. Applicability depends on the customer agreement and use case.

Not certified
βš–οΈ

ABA Rule 1.6

Architecture is intended to preserve attorney-client privilege during AI-assisted legal operations. Courts decide privilege. This is not a holding.

Design intent
Defense in Depth

Six Pillars of Security

Every request passes through multiple independent security boundaries before reaching compute.

Encryption at Rest & Transit

AES-256 for data at rest. TLS 1.3 for all transit. CMEK available for Enterprise tier.

Privilege Preservation

Zero-knowledge LLM routing is a design goal. Privilege is not guaranteed. Courts decide privilege.

Immutable Audit Trails

Every AI interaction cryptographically logged with tamper-evident checksums for regulatory review.

Tenant Isolation

Firm data logically and cryptographically isolated. Dedicated compute pools for Enterprise.

Data Residency

Choose US, EU, or APAC. Data never leaves your jurisdiction without explicit consent.

Zero-Trust Access

RBAC with MFA. SSO via SAML 2.0 & OIDC. Session tokens rotate every 15 minutes.

βš–οΈ

Heppner-Aware Architecture

Public marketing references post-Heppner discovery risk. Heppner v. Agentic Systems, Inc. outcomes are jurisdiction- and fact-specific. ShadowTagAI implements privilege-preservation guardrails as a design goal. This page is not an independent audit and does not certify a court result.

Infrastructure

Google Cloud Native Stack

ComponentTechnology
Cloud ProviderGoogle Cloud Platform
ComputeCloud Run (serverless, auto-scaling)
DatabaseFirestore + Cloud Spanner
CDN / EdgeCloud Armor + Firebase Hosting
WAFCloud Armor is available; this page does not prove a live rule count
MonitoringCloud Monitoring + 8 alert policies
CI/CDCloud Build with signed artifacts
SecretsGCP Secret Manager (FIPS 140-2)
Data Governance

Jurisdictional Compliance

πŸ‡ͺπŸ‡Ί

GDPR

30-day deletion queue via Cloud Tasks. Data Processing Agreements. Right to erasure with cryptographic verification. EU data residency available.

πŸ‡ΊπŸ‡Έ

CLOUD Act

All data stored on GCP in customer-selected jurisdiction. Transparent government request policies. Legal challenge commitments for overreach.

πŸ—‘οΈ

Retention

Retention is product-specific. This page does not claim universal zero data retention or cryptographic shredding as a default for every product.

Ready for a Security Review?

See Our Security in Action.

Schedule a deep-dive with our engineering team. We'll walk through architecture, provide audit documentation, and answer every question.

Request Security Review Back to Home