Security

RegShield AI handles your security policies and evidence. Protecting that data is the product. Here's how we do it.

Last updated June 2026

Data encryption

All traffic to RegShield AI is encrypted in transit with TLS 1.2+ (HTTPS everywhere, HSTS enabled). Data at rest — your database records and uploaded evidence files — is stored on encrypted volumes. Secrets and API keys are held in environment configuration, never committed to source control.

Tenant isolation

RegShield AI is multi-tenant. Every record — evidence, analyses, reports, framework activations — is scoped to your organization and filtered by your organization ID on every request. Authentication is enforced at every service boundary; a token issued for one organization cannot read another's data.

Access control & authentication

  • Passwords are hashed with bcrypt — we never store or can see your plaintext password.
  • Sessions use short-lived signed JWTs; platform-administration access is a separate, explicitly-granted privilege.
  • Role-based access within your workspace (owner / admin / member) governs who can invite teammates and manage settings.
  • Security-sensitive actions (logins, invites, customer provisioning, password resets) are recorded in an audit log.

Infrastructure

RegShield AI runs on enterprise-grade cloud infrastructure, with production data hosted in India by default. Two subprocessors process limited data outside India under data-processing agreements — see subprocessors. Network access is restricted to the public web and admin ports only; databases and internal services are not exposed to the public internet. The database is backed up on a regular schedule with point-in-time recovery.

AI processing

Document analysis uses OpenAI's API. Your evidence text is sent only to perform the analysis you request; under OpenAI's API terms, data submitted through the API is not used to train their models. Every third party that customer data reaches is named in our subprocessor list.

Vulnerability management & responsible disclosure

Dependencies are kept current and reviewed for known vulnerabilities. If you believe you've found a security issue, please email security@regshield.in— we'll acknowledge your report and work with you on a fix. Please give us reasonable time to remediate before any public disclosure.

Compliance posture

RegShield AI is built by a team that lives and breathes compliance frameworks. We hold ourselves to the same control expectations we help our customers meet (SOC 2, ISO 27001, GDPR, India's DPDPA). Formal third-party certifications are on our roadmap; this page describes the controls in place today. For a deeper security review or to request our latest documentation, contact security@regshield.in.