Home Events Overview Capabilities Engagements Fractional CSO Exposure Assessment SHDW App The Team Deploy Now
Trust

SECURITY

How we protect the information you trust us with

Encrypted In Transit & At Rest· Least Privilege Access· Client Isolation· Audited Access· Confidential By Design· Encrypted In Transit & At Rest· Least Privilege Access· Client Isolation· Audited Access· Confidential By Design·

Shadow exists to protect people. That same standard governs how we protect the information you place in our care: the codes to a residence, the details that identify a principal, the plan for where a detail will be. Security is not a feature we added; it is how the platform is built.

Below is a plain description of how we safeguard your data. No system is ever perfectly secure, but we hold your information to the same discipline we bring to a protective assignment.

Encryption

Encrypted in transit and at rest

Every connection is protected with strong, industry-standard transport encryption. The most sensitive records, including access codes and protective details, are encrypted at the field level, and the keys that unlock them are held separately from the database, so the stored data is unreadable on its own.

Access

Least privilege, need to know

People see only what their role requires. The most sensitive records are hidden by default and shown only through a deliberate, recorded action. Privileged and administrative accounts are protected with multi-factor authentication.

Isolation

Separated by client

Every organization's information is kept separate from every other's. Automated checks run continuously against the platform to guard against any path that could cross that boundary, before changes ever reach you.

Accountability

Every sensitive view is on the record

Access to protected records is logged. When a code or a dossier is viewed or exported, we capture who did it and when, so there is always an accountable trail behind the most sensitive information.

Confidentiality

Internal by design

Protective dossiers and client intelligence are strictly internal and never appear on a client-facing document. Information is kept only as long as it is operationally or legally necessary, then securely disposed of.

Diligence

Hardened continuously

We treat our own platform the way we treat a protective assignment: reviewed, tested, and improved on an ongoing basis. If you believe you have found a security issue, we want to hear from you at hello@shdw.com.

Responsible Disclosure

We welcome reports from security researchers acting in good faith. If you believe you have found a vulnerability in this website or the SHDW App, please tell us before disclosing it publicly and give us a reasonable opportunity to fix it.

How to report. Email hello@shdw.com with a clear description, the steps to reproduce, and the potential impact. Our machine-readable contact details are published at /.well-known/security.txt.

Please do. Test only against your own accounts or data you are authorized to use, stop as soon as you have demonstrated a problem, and give us time to remediate before going public.

Please do not. Access, modify, or delete data that is not yours; degrade or disrupt the service; run automated scans that generate excessive traffic; or attempt to socially engineer our team, our providers, or our clients. Never test against real protective, principal, or client information.

Safe harbor. If you make a good-faith effort to follow this policy, we will treat your research as authorized, will not pursue or support legal action against you for it, and will work with you to understand and resolve the issue quickly. We do not run a paid bounty program at this time, but we gratefully acknowledge researchers who help us protect the people we serve.

For enterprise and government security reviews

A detailed security and data-protection brief, covering our controls in greater depth, is available to qualified reviewers under NDA. To request it, or to route a vendor security questionnaire, contact hello@shdw.com.

Last Updated: July 2026