Encryption
Your data is encrypted in transit (TLS 1.2+) and at rest using industry-standard algorithms.
Security & trust
Shield360 collects only the information needed to give you useful cybersecurity guidance. Here is how that information is handled.
Your data is encrypted in transit (TLS 1.2+) and at rest using industry-standard algorithms.
Passwords are hashed with a strong, recognised algorithm. We never store plaintext passwords.
Access to your data is scoped to your organisation. Admins, team members and trainers only see what they need.
Automated backups protect against data loss and are held under the same access controls as the live database.
You can export your business data at any time. Your information is yours.
You can delete your account and request permanent deletion of your business data at any time.
Assessment responses
Used only to calculate your score, generate your action plan and improve your recommendations. Not sold to third parties.
Account data
Stored securely with role-based access. You can update or delete it from your account settings.
AI usage
AI prompts are used to answer your question and improve future prompts. We do not train models on customer data by default.
Data retention
Data is kept while your account is active. On deletion, we remove your data within 30 days, subject to legal retention requirements.
Third-party services
We rely on vetted infrastructure providers for hosting, email and analytics. See our Privacy Policy for the current list.
Incident reporting
If we detect a security incident affecting customer data, we notify affected customers as required by applicable law.
We do not display badges we have not earned. Shield360 does not currently claim ISO 27001, SOC 2, PCI DSS, GDPR or NDPR certification. We follow the practices those frameworks are built around and will publish certification status once formally completed.