Frequently asked questions

Pulled from the security questions we're asked most often. If yours isn't here, email shine@outsellconsulting.com.

Is SHINE AI SOC 2 compliant?+

We have completed our SOC 2 Type 1 examination. The report is available under NDA via the Request Access flow. A Type 2 examination is planned to follow.

How is customer data encrypted?+

Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Encryption keys are managed by our infrastructure providers' managed key services.

Where is customer data hosted?+

Primary hosting is on Digital Ocean (application infrastructure) and Planetscale (primary database), both in US regions. A full list of subprocessors is available on our Subprocessors page.

Do you use customer data to train models?+

No. Customer meeting content is not used to train any model — ours or a subprocessor's. LLM subprocessors (OpenAI, Google Gemini) are contractually bound to zero data retention for training.

How do you authenticate users?+

Authentication is handled by our in-house auth service, running on Google Cloud Platform against a dedicated Postgres database that we operate. Password-based accounts support MFA, and MFA is required for administrative access. SSO (Google, Microsoft, SAML 2.0) is available for enterprise customers on request.

How long is customer data retained?+

Meeting content is retained per the customer's configured retention policy. On termination, data is deleted within 30 days unless a longer period is required by law.

How do you handle security incidents?+

We follow a documented Incident Response Policy with defined severity classifications, on-call rotation, customer notification within 72 hours of confirmed impact, and post-incident review.

Do you perform penetration testing?+

Yes. An independent third party performs an application and infrastructure penetration test at least annually. The executive summary is available under NDA.

What is your uptime target?+

Our target is 99.9% monthly uptime for the production service. SLA terms are specified in enterprise contracts.

How do I report a security vulnerability?+

Email shine@outsellconsulting.com. We acknowledge reports within one business day and coordinate disclosure with the reporter.