Security & trust

Your trust matters

Shield360 collects only the information needed to give you useful cybersecurity guidance. Here is how that information is handled.

Encryption

Your data is encrypted in transit (TLS 1.2+) and at rest using industry-standard algorithms.

Password protection

Passwords are hashed with a strong, recognised algorithm. We never store plaintext passwords.

Role-based access

Access to your data is scoped to your organisation. Admins, team members and trainers only see what they need.

Backups

Automated backups protect against data loss and are held under the same access controls as the live database.

Data export

You can export your business data at any time. Your information is yours.

Data deletion

You can delete your account and request permanent deletion of your business data at any time.

Data handling in plain English

  • Assessment responses

    Used only to calculate your score, generate your action plan and improve your recommendations. Not sold to third parties.

  • Account data

    Stored securely with role-based access. You can update or delete it from your account settings.

  • AI usage

    AI prompts are used to answer your question and improve future prompts. We do not train models on customer data by default.

  • Data retention

    Data is kept while your account is active. On deletion, we remove your data within 30 days, subject to legal retention requirements.

  • Third-party services

    We rely on vetted infrastructure providers for hosting, email and analytics. See our Privacy Policy for the current list.

  • Incident reporting

    If we detect a security incident affecting customer data, we notify affected customers as required by applicable law.

Certifications

We do not display badges we have not earned. Shield360 does not currently claim ISO 27001, SOC 2, PCI DSS, GDPR or NDPR certification. We follow the practices those frameworks are built around and will publish certification status once formally completed.