Trust Center
Security at Shineon
Shineon Intelligence LIMITED builds AI agents and services that orchestrate multiple models behind a single interface. That means your inputs pass through our infrastructure and, for inference, onward to upstream model providers. This page documents how we protect them, which controls we operate, and exactly who those upstream providers are.
Frameworks
Compliance
Where each framework actually stands today. We list observation periods and audit stages rather than badges alone, so a reviewer can tell the difference between an issued report and work in flight.
SOC 2 Type II
Continuously auditedIndependent examination of the design and operating effectiveness of Shineon's controls against the AICPA Trust Services Criteria for Security, Availability, and Confidentiality over a continuous observation period.
- Period
- Continuous observation window, opened April 1, 2026
GDPR
Continuously monitoredShineon acts as a data processor for customer content. A Data Processing Addendum with EU Standard Contractual Clauses is available to all customers on request.
CCPA / CPRA
Continuously monitoredShineon does not sell or share personal information as those terms are defined by the CCPA. California residents may exercise access and deletion rights through our privacy contact.
Evidence
Documents
The policies that govern how Shineon handles your data, published in full.
Trust Services Criteria
Controls
The 33 controls Shineon operates, grouped the way a SOC 2 reviewer reads them. Each is monitored continuously rather than assembled at audit time.
Infrastructure
6 controlsHow the environments that run the Shineon platform, its orchestration layer, and the model gateway are built and defended.
Unique production database authentication enforced
Each engineer authenticates to production data stores with an individually attributable credential. Shared database accounts are not issued.
Encryption key access restricted
Access to key management systems is limited to the infrastructure on-call rotation and reviewed each quarter.
Network firewalls reviewed
Ingress and egress rules for production networks are reviewed at least annually and after any change to the perimeter.
Infrastructure changes are peer reviewed
Infrastructure is declared as code. Changes require an approving review from a second engineer before they can be applied.
Production environment segregated
Development, staging, and production run in isolated accounts with no shared credentials or network paths.
Continuous infrastructure monitoring
Cloud resources are continuously evaluated against a hardening baseline; drift raises a ticket to the owning team.
Organizational
6 controlsHow Shineon staffs, trains, and holds its people accountable.
Background checks performed
Criminal, education, and employment history checks are completed for new personnel where local law permits.
Security awareness training completed
All personnel complete security and privacy training on hire and annually thereafter.
Confidentiality agreements acknowledged
Employees and contractors sign confidentiality terms covering customer content and inputs before receiving access.
Code of conduct acknowledged
Personnel acknowledge the code of conduct at onboarding and on each annual refresh.
Performance and disciplinary process defined
A documented process governs how policy violations are investigated and remediated.
Asset inventory maintained
Company-issued endpoints are inventoried, encrypted at rest, and enrolled in mobile device management.
Product Security
7 controlsControls that live in the products themselves — authentication, API keys, tenancy, and the model orchestration path.
Data encrypted in transit
All traffic to the platform and onward to upstream model providers is carried over TLS 1.2 or higher.
Data encrypted at rest
Customer inputs, generated outputs, and database contents are encrypted at rest with AES-256.
API keys scoped and revocable
Keys are issued per account, stored only as hashes, displayed once at creation, and can be revoked instantly by the customer.
Tenant isolation enforced
Every request carries the caller's tenant context, and storage paths for customer content are namespaced per account.
Rate limiting and abuse detection
Per-key rate limits and anomaly detection on usage volume protect against credential abuse and runaway spend.
Dependency and container scanning
Application dependencies and images are scanned on every build; findings are triaged against a severity-based SLA.
Penetration testing performed
An independent firm tests the application and its public API at least annually; findings are tracked to closure.
Internal Security Procedures
6 controlsHow Shineon detects, responds to, and recovers from incidents.
Incident response plan tested
A documented incident response plan assigns roles and communication paths, and is exercised at least annually.
Customer notification commitment
Customers affected by a confirmed security incident involving their data are notified without undue delay.
Access reviews conducted
Access to production systems and third-party services is reviewed quarterly; unnecessary grants are removed.
Offboarding checklist enforced
Access is revoked and devices reclaimed as part of a tracked checklist on the departure date.
Continuity and recovery plan maintained
Business continuity and disaster recovery plans define recovery objectives and are reviewed annually.
Backups performed and restore-tested
Production data is backed up on a defined schedule, and restores are tested rather than assumed.
Data and Privacy
8 controlsWhat happens to customer inputs and generated outputs — including what is sent to upstream model providers.
Zero data retention at the model layer
Inference inputs and outputs are held in memory only for the life of the request and are never persisted at the model invocation layer. Upstream providers are contractually bound to the same, and a provider that cannot meet it is not routed to.
Operational data residency
Account, billing, API key, usage, and log data — and any content a customer saves into their account — are stored in Singapore.
Customer content is not used to train models
Shineon does not train models on customer inputs or generated outputs, and requires the same of the upstream providers it routes to.
Upstream providers disclosed
The model providers a request may be routed to are disclosed in the subprocessor list and in the Data Processing Addendum.
Retention periods defined
Retention windows are defined per data class, and content is deleted or anonymized once its window closes.
Deletion requests honored
Account deletion removes customer content, inputs, and generated outputs from production systems within the published window.
Data classification policy applied
Data is classified on a defined scale, and handling requirements follow the classification.
Privacy policy published and maintained
A public privacy policy describes collection, use, cross-border transfer, and the rights available to data subjects.
Third parties
Subprocessors
Because Shineon routes inference requests to models it does not host, the upstream providers are part of your data flow. All of them are listed here, not just our own infrastructure vendors.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Amazon Web Services | Cloud infrastructure, hosting, and upstream model inference | Account and operational data, inputs submitted for inference | Singapore (ap-southeast-1) |
| Cloudflare | CDN, DNS, and DDoS protection | IP addresses, request metadata | United States |
| Upstream model inference | Inputs submitted for inference | United States | |
| ByteDance | Upstream model inference | Inputs submitted for inference | Singapore |
| Stripe | Payment processing and billing | Billing contact and transaction records | United States |
Customers with a signed Data Processing Addendum receive advance notice before a new subprocessor is added.
Governance
Policies
Reviewed and re-approved annually, and acknowledged by every member of staff.
- Information Security Policy
- Access Control Policy
- Acceptable Use Policy
- Data Classification & Retention Policy
- Encryption & Key Management Policy
- Incident Response Plan
- Business Continuity & Disaster Recovery Plan
- Secure Software Development Policy
- Vendor & Subprocessor Management Policy
- Risk Assessment & Treatment Policy
Changelog
Updates
Material changes to Shineon's security posture, compliance status, and subprocessor list.
Privacy Policy revised
Clarified cross-border transfer language for requests routed to upstream model providers outside the customer's region.
SOC 2 Type II observation period opened
Shineon began its continuous observation window against the Security, Availability, and Confidentiality Trust Services Criteria.
Trust Center published
Shineon's security posture, control set, and subprocessor list are now available in one place.
Common questions
FAQ
The questions that come up most often in customer security reviews.
Do you train models on my content?
No. Customer inputs and generated outputs are not used to train Shineon or upstream provider models, and the model layer runs zero data retention — nothing is persisted there to train on. Both are contracted with each upstream provider, not merely assumed.
Where is my data processed?
Operational data — your account, billing, API key, usage, and log records, plus anything you save into your account — is stored in Singapore. Inference itself is zero-retention: an inference request is transmitted to whichever upstream provider the orchestrator routes it to, processed in memory, and not persisted at that layer. Those providers and their regions are listed in the subprocessor table above.
Can I sign a DPA?
Yes. Our Data Processing Addendum incorporates the EU Standard Contractual Clauses and is available to every customer regardless of plan. Get in touch and we will send it over.
How do I report a vulnerability?
Email contact@shineon.dev with reproduction steps. We acknowledge reports within one business day and will keep you updated through remediation. We do not pursue legal action against good-faith research.
How are subprocessor changes communicated?
New subprocessors are posted to this page and announced in the Updates feed. Customers with a signed DPA receive advance notice and may object under the terms of that agreement.
Running a security review?
Send us your questionnaire, or just the question that is blocking you. Our security team answers directly — no ticket queue in between.
contact@shineon.dev