Summaries of the policies that govern the SHINE AI security program. The full policy documents are available under NDA — request access from any policy card.
The overarching policy that governs our security program — scope, roles, exceptions, and the annual review cadence.
Least-privilege by default. SSO with MFA is required for administrative access. Access is provisioned via a documented request-and-approve flow and reviewed quarterly.
24×7 on-call rotation. Incidents are classified by severity, tracked to closure, and communicated to affected customers within 72 hours of confirmed impact.
Automated multi-AZ backups, documented RTO/RPO, and annual tabletop exercises. Restore procedures are tested and results retained as audit evidence.
Every vendor that touches customer data is risk-assessed, subject to a signed DPA, and re-reviewed annually. Material changes are announced to customers with 30 days' notice.
Risks are identified in a central register, scored on likelihood and impact, and assigned an owner. The register is reviewed at least quarterly and reported to leadership.
Code review is required for all production changes. Dependencies are scanned continuously. Secrets are never committed — pre-commit and CI checks enforce this.
Customer content is classified as Confidential by default. Storage, transit, retention, and disposal rules are defined per classification level.