Policies

Summaries of the policies that govern the SHINE AI security program. The full policy documents are available under NDA — request access from any policy card.

Information Security

The overarching policy that governs our security program — scope, roles, exceptions, and the annual review cadence.

Access Control

Least-privilege by default. SSO with MFA is required for administrative access. Access is provisioned via a documented request-and-approve flow and reviewed quarterly.

Incident Response

24×7 on-call rotation. Incidents are classified by severity, tracked to closure, and communicated to affected customers within 72 hours of confirmed impact.

Business Continuity & Disaster Recovery

Automated multi-AZ backups, documented RTO/RPO, and annual tabletop exercises. Restore procedures are tested and results retained as audit evidence.

Vendor / Subprocessor Management

Every vendor that touches customer data is risk-assessed, subject to a signed DPA, and re-reviewed annually. Material changes are announced to customers with 30 days' notice.

Risk Management

Risks are identified in a central register, scored on likelihood and impact, and assigned an owner. The register is reviewed at least quarterly and reported to leadership.

Secure SDLC

Code review is required for all production changes. Dependencies are scanned continuously. Secrets are never committed — pre-commit and CI checks enforce this.

Data Classification & Handling

Customer content is classified as Confidential by default. Storage, transit, retention, and disposal rules are defined per classification level.