Every layer of ShadowTagAI is built for zero-trust data sovereignty. From encryption at rest to tenant isolation β security is structural, not bolted on.
Annual audit covering security, availability, and confidentiality trust service criteria. No Type II report is published here.
Not certifiedData Processing Agreements may be offered for international deployments. This is not a certification badge.
Not a certificationBAA-ready design is not a blanket HIPAA certification. Applicability depends on the customer agreement and use case.
Not certifiedArchitecture is intended to preserve attorney-client privilege during AI-assisted legal operations. Courts decide privilege. This is not a holding.
Design intentEvery request passes through multiple independent security boundaries before reaching compute.
AES-256 for data at rest. TLS 1.3 for all transit. CMEK available for Enterprise tier.
Zero-knowledge LLM routing is a design goal. Privilege is not guaranteed. Courts decide privilege.
Every AI interaction cryptographically logged with tamper-evident checksums for regulatory review.
Firm data logically and cryptographically isolated. Dedicated compute pools for Enterprise.
Choose US, EU, or APAC. Data never leaves your jurisdiction without explicit consent.
RBAC with MFA. SSO via SAML 2.0 & OIDC. Session tokens rotate every 15 minutes.
| Component | Technology |
|---|---|
| Cloud Provider | Google Cloud Platform |
| Compute | Cloud Run (serverless, auto-scaling) |
| Database | Firestore + Cloud Spanner |
| CDN / Edge | Cloud Armor + Firebase Hosting |
| WAF | Cloud Armor is available; this page does not prove a live rule count |
| Monitoring | Cloud Monitoring + 8 alert policies |
| CI/CD | Cloud Build with signed artifacts |
| Secrets | GCP Secret Manager (FIPS 140-2) |
30-day deletion queue via Cloud Tasks. Data Processing Agreements. Right to erasure with cryptographic verification. EU data residency available.
All data stored on GCP in customer-selected jurisdiction. Transparent government request policies. Legal challenge commitments for overreach.
Retention is product-specific. This page does not claim universal zero data retention or cryptographic shredding as a default for every product.
Schedule a deep-dive with our engineering team. We'll walk through architecture, provide audit documentation, and answer every question.