Document library

Public documents are downloadable directly. Documents marked NDA are available after signing our mutual NDA, request access and we'll respond within one business day.

Compliance

2 documents

SOC 2 Type 1 Report

NDA

Independent auditor's report on the design of SHINE AI's security controls against the AICPA Trust Services Criteria (Security).

Pending — expected within 1 weekRequest →

SOC 3 Report

Public

Public summary of our SOC 2 examination, suitable for general distribution.

Planned — post-Type 1Request →

Security

5 documents

Penetration Test Summary (Latest)

NDA

Executive summary of the most recent third-party penetration test, including scope, methodology, findings by severity, and remediation status.

Updated per test cycleRequest →

Vulnerability Management Overview

Public

How we scan, triage, and remediate vulnerabilities across application code, dependencies, and infrastructure.

Security Overview (Whitepaper)

Public

Plain-English summary of how SHINE AI protects customer data — encryption, tenancy model, authentication, and monitoring.

RollingView →

Architecture Overview

NDA

High-level system diagram and description of application, data, and infrastructure boundaries.

CAIQ / Standard Security Questionnaire Response

NDA

Pre-filled responses to the Cloud Security Alliance CAIQ (and equivalents) to short-circuit vendor security reviews.

Policies

10 documents

Information Security Policy

NDA

Top-level policy governing the information security program, roles, and responsibilities.

Reviewed annuallyRequest →

Access Control Policy

NDA

Identity, authentication, authorization, and least-privilege standards across production and corporate systems.

Reviewed annuallyRequest →

Incident Response Policy

NDA

How security incidents are detected, classified, escalated, communicated, and post-mortemed.

Reviewed annuallyRequest →

Business Continuity & Disaster Recovery Plan

NDA

RTO/RPO targets, backup strategy, failover procedures, and tabletop exercise cadence.

Reviewed annuallyRequest →

Vendor / Subprocessor Management Policy

NDA

Risk assessment, DPA execution, and ongoing monitoring for third-party services.

Reviewed annuallyRequest →

Risk Management Policy

NDA

Framework for identifying, scoring, treating, and reviewing enterprise and information security risks.

Reviewed annuallyRequest →

Secure SDLC Policy

NDA

Code review, dependency management, secret scanning, and pre-release security gates.

Reviewed annuallyRequest →

Data Classification & Handling Policy

NDA

How customer and internal data is classified, stored, transmitted, retained, and disposed of.

Reviewed annuallyRequest →

Acceptable Use Policy

NDA

Employee obligations for endpoint, network, and SaaS usage.

Reviewed annuallyRequest →

Endpoint & Encryption Policy

NDA

MDM, disk encryption, screen lock, and anti-malware requirements for workforce devices.

Reviewed annuallyRequest →

Privacy

2 documents

Privacy Policy

Public

How SHINE AI collects, uses, shares, and protects personal information.

See documentView →

List of Subprocessors

Public

Current third-party service providers that process customer data.

See pageView →

Legal

1 document

Terms of Service

Public

Master terms governing use of SHINE AI.

See documentView →

Operational

1 document

Service Level Agreement

Customers only

Uptime commitments, support response targets, and remedies.

Per contractRequest →