Public documents are downloadable directly. Documents marked NDA are available after signing our mutual NDA, request access and we'll respond within one business day.
Independent auditor's report on the design of SHINE AI's security controls against the AICPA Trust Services Criteria (Security).
Public summary of our SOC 2 examination, suitable for general distribution.
Executive summary of the most recent third-party penetration test, including scope, methodology, findings by severity, and remediation status.
How we scan, triage, and remediate vulnerabilities across application code, dependencies, and infrastructure.
Plain-English summary of how SHINE AI protects customer data — encryption, tenancy model, authentication, and monitoring.
High-level system diagram and description of application, data, and infrastructure boundaries.
Pre-filled responses to the Cloud Security Alliance CAIQ (and equivalents) to short-circuit vendor security reviews.
Top-level policy governing the information security program, roles, and responsibilities.
Identity, authentication, authorization, and least-privilege standards across production and corporate systems.
How security incidents are detected, classified, escalated, communicated, and post-mortemed.
RTO/RPO targets, backup strategy, failover procedures, and tabletop exercise cadence.
Risk assessment, DPA execution, and ongoing monitoring for third-party services.
Framework for identifying, scoring, treating, and reviewing enterprise and information security risks.
Code review, dependency management, secret scanning, and pre-release security gates.
How customer and internal data is classified, stored, transmitted, retained, and disposed of.
Employee obligations for endpoint, network, and SaaS usage.
MDM, disk encryption, screen lock, and anti-malware requirements for workforce devices.
Uptime commitments, support response targets, and remedies.