Live · Updated regularly

Security and compliance at SHINE AI

SHINE AI is the meeting intelligence platform for industrial and manufacturing sales teams. This is where we publish how we protect your data — the certifications we hold, the policies we follow, and the documents your security team needs to close review.

SOC 2 Type 1
Certified — report available under NDA
SOC 2 Type 2
Planned — observation window in progress
GDPR
DPA + SCCs available on request
Encryption
TLS 1.2+ in transit · AES-256 at rest

How we approach security

Four pillars mapped to the AICPA Trust Services Criteria that our SOC 2 program is audited against.

Data protection

Customer meeting audio and transcripts are encrypted end-to-end, logically isolated per tenant, and never used to train models — ours or a subprocessor's.

Access control

SSO (Google, Microsoft, SAML), MFA on all administrative access, least-privilege IAM, and full audit logging of production access.

Availability

Redundant deployment across multiple regions, automated backups, documented RTO/RPO targets, and quarterly recovery testing.

Vendor risk

Every subprocessor reviewed against our vendor policy with a signed DPA. Current subprocessor list is public and versioned.

Most requested documents

What your security team is probably looking for.

SOC 2 Type 1 Report
Independent auditor's report on the design of SHINE AI's security controls against the AICPA Trust Services Criteria (Security).
Request →
Penetration Test Summary (Latest)
Executive summary of the most recent third-party penetration test, including scope, methodology, findings by severity, and remediation status.
Request →
List of Subprocessors
Current third-party service providers that process customer data.
View →

Something else your security team needs?

Reach us at shine@outsellconsulting.com. For vulnerability reports, please include steps to reproduce.

Request access