SECURITY
How we protect the information you trust us with
Shadow exists to protect people. That same standard governs how we protect the information you place in our care: the codes to a residence, the details that identify a principal, the plan for where a detail will be. Security is not a feature we added; it is how the platform is built.
Below is a plain description of how we safeguard your data. No system is ever perfectly secure, but we hold your information to the same discipline we bring to a protective assignment.
Encrypted in transit and at rest
Every connection is protected with strong, industry-standard transport encryption. The most sensitive records, including access codes and protective details, are encrypted at the field level, and the keys that unlock them are held separately from the database, so the stored data is unreadable on its own.
Least privilege, need to know
People see only what their role requires. The most sensitive records are hidden by default and shown only through a deliberate, recorded action. Privileged and administrative accounts are protected with multi-factor authentication.
Separated by client
Every organization's information is kept separate from every other's. Automated checks run continuously against the platform to guard against any path that could cross that boundary, before changes ever reach you.
Every sensitive view is on the record
Access to protected records is logged. When a code or a dossier is viewed or exported, we capture who did it and when, so there is always an accountable trail behind the most sensitive information.
Internal by design
Protective dossiers and client intelligence are strictly internal and never appear on a client-facing document. Information is kept only as long as it is operationally or legally necessary, then securely disposed of.
Hardened continuously
We treat our own platform the way we treat a protective assignment: reviewed, tested, and improved on an ongoing basis. If you believe you have found a security issue, we want to hear from you at hello@shdw.com.
Responsible Disclosure
We welcome reports from security researchers acting in good faith. If you believe you have found a vulnerability in this website or the SHDW App, please tell us before disclosing it publicly and give us a reasonable opportunity to fix it.
How to report. Email hello@shdw.com with a clear description, the steps to reproduce, and the potential impact. Our machine-readable contact details are published at /.well-known/security.txt.
Please do. Test only against your own accounts or data you are authorized to use, stop as soon as you have demonstrated a problem, and give us time to remediate before going public.
Please do not. Access, modify, or delete data that is not yours; degrade or disrupt the service; run automated scans that generate excessive traffic; or attempt to socially engineer our team, our providers, or our clients. Never test against real protective, principal, or client information.
Safe harbor. If you make a good-faith effort to follow this policy, we will treat your research as authorized, will not pursue or support legal action against you for it, and will work with you to understand and resolve the issue quickly. We do not run a paid bounty program at this time, but we gratefully acknowledge researchers who help us protect the people we serve.
A detailed security and data-protection brief, covering our controls in greater depth, is available to qualified reviewers under NDA. To request it, or to route a vendor security questionnaire, contact hello@shdw.com.
Last Updated: July 2026