Trust Center

Security at Shineon

Shineon Intelligence LIMITED builds AI agents and services that orchestrate multiple models behind a single interface. That means your inputs pass through our infrastructure and, for inference, onward to upstream model providers. This page documents how we protect them, which controls we operate, and exactly who those upstream providers are.

Frameworks

Compliance

Where each framework actually stands today. We list observation periods and audit stages rather than badges alone, so a reviewer can tell the difference between an issued report and work in flight.

SOC 2 Type II

Continuously audited

Independent examination of the design and operating effectiveness of Shineon's controls against the AICPA Trust Services Criteria for Security, Availability, and Confidentiality over a continuous observation period.

Period
Continuous observation window, opened April 1, 2026

GDPR

Continuously monitored

Shineon acts as a data processor for customer content. A Data Processing Addendum with EU Standard Contractual Clauses is available to all customers on request.

CCPA / CPRA

Continuously monitored

Shineon does not sell or share personal information as those terms are defined by the CCPA. California residents may exercise access and deletion rights through our privacy contact.

Evidence

Documents

The policies that govern how Shineon handles your data, published in full.

  • Privacy Policy

    What Shineon collects, where it is stored, how long it is retained, and the rights available to you.

    Open
  • Terms of Service

    The agreement governing use of the Shineon platform.

    Open

Trust Services Criteria

Controls

The 33 controls Shineon operates, grouped the way a SOC 2 reviewer reads them. Each is monitored continuously rather than assembled at audit time.

Infrastructure

6 controls

How the environments that run the Shineon platform, its orchestration layer, and the model gateway are built and defended.

  • Unique production database authentication enforced

    Each engineer authenticates to production data stores with an individually attributable credential. Shared database accounts are not issued.

  • Encryption key access restricted

    Access to key management systems is limited to the infrastructure on-call rotation and reviewed each quarter.

  • Network firewalls reviewed

    Ingress and egress rules for production networks are reviewed at least annually and after any change to the perimeter.

  • Infrastructure changes are peer reviewed

    Infrastructure is declared as code. Changes require an approving review from a second engineer before they can be applied.

  • Production environment segregated

    Development, staging, and production run in isolated accounts with no shared credentials or network paths.

  • Continuous infrastructure monitoring

    Cloud resources are continuously evaluated against a hardening baseline; drift raises a ticket to the owning team.

Organizational

6 controls

How Shineon staffs, trains, and holds its people accountable.

  • Background checks performed

    Criminal, education, and employment history checks are completed for new personnel where local law permits.

  • Security awareness training completed

    All personnel complete security and privacy training on hire and annually thereafter.

  • Confidentiality agreements acknowledged

    Employees and contractors sign confidentiality terms covering customer content and inputs before receiving access.

  • Code of conduct acknowledged

    Personnel acknowledge the code of conduct at onboarding and on each annual refresh.

  • Performance and disciplinary process defined

    A documented process governs how policy violations are investigated and remediated.

  • Asset inventory maintained

    Company-issued endpoints are inventoried, encrypted at rest, and enrolled in mobile device management.

Product Security

7 controls

Controls that live in the products themselves — authentication, API keys, tenancy, and the model orchestration path.

  • Data encrypted in transit

    All traffic to the platform and onward to upstream model providers is carried over TLS 1.2 or higher.

  • Data encrypted at rest

    Customer inputs, generated outputs, and database contents are encrypted at rest with AES-256.

  • API keys scoped and revocable

    Keys are issued per account, stored only as hashes, displayed once at creation, and can be revoked instantly by the customer.

  • Tenant isolation enforced

    Every request carries the caller's tenant context, and storage paths for customer content are namespaced per account.

  • Rate limiting and abuse detection

    Per-key rate limits and anomaly detection on usage volume protect against credential abuse and runaway spend.

  • Dependency and container scanning

    Application dependencies and images are scanned on every build; findings are triaged against a severity-based SLA.

  • Penetration testing performed

    An independent firm tests the application and its public API at least annually; findings are tracked to closure.

Internal Security Procedures

6 controls

How Shineon detects, responds to, and recovers from incidents.

  • Incident response plan tested

    A documented incident response plan assigns roles and communication paths, and is exercised at least annually.

  • Customer notification commitment

    Customers affected by a confirmed security incident involving their data are notified without undue delay.

  • Access reviews conducted

    Access to production systems and third-party services is reviewed quarterly; unnecessary grants are removed.

  • Offboarding checklist enforced

    Access is revoked and devices reclaimed as part of a tracked checklist on the departure date.

  • Continuity and recovery plan maintained

    Business continuity and disaster recovery plans define recovery objectives and are reviewed annually.

  • Backups performed and restore-tested

    Production data is backed up on a defined schedule, and restores are tested rather than assumed.

Data and Privacy

8 controls

What happens to customer inputs and generated outputs — including what is sent to upstream model providers.

  • Zero data retention at the model layer

    Inference inputs and outputs are held in memory only for the life of the request and are never persisted at the model invocation layer. Upstream providers are contractually bound to the same, and a provider that cannot meet it is not routed to.

  • Operational data residency

    Account, billing, API key, usage, and log data — and any content a customer saves into their account — are stored in Singapore.

  • Customer content is not used to train models

    Shineon does not train models on customer inputs or generated outputs, and requires the same of the upstream providers it routes to.

  • Upstream providers disclosed

    The model providers a request may be routed to are disclosed in the subprocessor list and in the Data Processing Addendum.

  • Retention periods defined

    Retention windows are defined per data class, and content is deleted or anonymized once its window closes.

  • Deletion requests honored

    Account deletion removes customer content, inputs, and generated outputs from production systems within the published window.

  • Data classification policy applied

    Data is classified on a defined scale, and handling requirements follow the classification.

  • Privacy policy published and maintained

    A public privacy policy describes collection, use, cross-border transfer, and the rights available to data subjects.

Third parties

Subprocessors

Because Shineon routes inference requests to models it does not host, the upstream providers are part of your data flow. All of them are listed here, not just our own infrastructure vendors.

SubprocessorPurposeData processedLocation
Amazon Web ServicesCloud infrastructure, hosting, and upstream model inferenceAccount and operational data, inputs submitted for inferenceSingapore (ap-southeast-1)
CloudflareCDN, DNS, and DDoS protectionIP addresses, request metadataUnited States
GoogleUpstream model inferenceInputs submitted for inferenceUnited States
ByteDanceUpstream model inferenceInputs submitted for inferenceSingapore
StripePayment processing and billingBilling contact and transaction recordsUnited States

Customers with a signed Data Processing Addendum receive advance notice before a new subprocessor is added.

Governance

Policies

Reviewed and re-approved annually, and acknowledged by every member of staff.

  • Information Security Policy
  • Access Control Policy
  • Acceptable Use Policy
  • Data Classification & Retention Policy
  • Encryption & Key Management Policy
  • Incident Response Plan
  • Business Continuity & Disaster Recovery Plan
  • Secure Software Development Policy
  • Vendor & Subprocessor Management Policy
  • Risk Assessment & Treatment Policy

Changelog

Updates

Material changes to Shineon's security posture, compliance status, and subprocessor list.

  1. Privacy Policy revised

    Clarified cross-border transfer language for requests routed to upstream model providers outside the customer's region.

  2. SOC 2 Type II observation period opened

    Shineon began its continuous observation window against the Security, Availability, and Confidentiality Trust Services Criteria.

  3. Trust Center published

    Shineon's security posture, control set, and subprocessor list are now available in one place.

Common questions

FAQ

The questions that come up most often in customer security reviews.

Do you train models on my content?

No. Customer inputs and generated outputs are not used to train Shineon or upstream provider models, and the model layer runs zero data retention — nothing is persisted there to train on. Both are contracted with each upstream provider, not merely assumed.

Where is my data processed?

Operational data — your account, billing, API key, usage, and log records, plus anything you save into your account — is stored in Singapore. Inference itself is zero-retention: an inference request is transmitted to whichever upstream provider the orchestrator routes it to, processed in memory, and not persisted at that layer. Those providers and their regions are listed in the subprocessor table above.

Can I sign a DPA?

Yes. Our Data Processing Addendum incorporates the EU Standard Contractual Clauses and is available to every customer regardless of plan. Get in touch and we will send it over.

How do I report a vulnerability?

Email contact@shineon.dev with reproduction steps. We acknowledge reports within one business day and will keep you updated through remediation. We do not pursue legal action against good-faith research.

How are subprocessor changes communicated?

New subprocessors are posted to this page and announced in the Updates feed. Customers with a signed DPA receive advance notice and may object under the terms of that agreement.

Running a security review?

Send us your questionnaire, or just the question that is blocking you. Our security team answers directly — no ticket queue in between.

contact@shineon.dev