# Security & Compliance

Shine handles real customer voices, recordings, and consent. We treat that data with the controls an enterprise security team expects, and we are transparent about where we are and where we are headed.

## Current status

- SOC 2 Type II: planned
- GDPR and CCPA: aligned
- Independent penetration test: planned

## Data protection

- Encrypted in transit (TLS 1.2+) and at rest across all surfaces.
- Field-level AES-256-GCM encryption on stored credentials such as OAuth tokens and third-party API keys.
- Customer recordings and records hosted on AWS in the United States.
- AI providers used strictly as processors, with model-training opt-out set on every customer-data call.

## Access & authentication

- Authentication via one-time passcodes and Google sign-in.
- Role-based access control with tenant isolation, enforced at the data layer and continuously tested.
- Secrets in AWS KMS-encrypted stores; no standing SSH access (operator access via session management); keyless CI using short-lived OIDC credentials.
- Abuse protection: rate limiting, Cloudflare Turnstile, and fail-closed guards.

## Infrastructure & monitoring

- Zero known production dependency vulnerabilities, monitored continuously.
- Hourly, KMS-encrypted, write-only backups against a documented restore-drill runbook.
- Parameterized queries and validated inputs throughout.
- Structured logging and observability with correlation IDs across pipelines.

## Privacy & your data rights

- Self-service data export for account holders; a maintained Data Protection Impact Assessment (DPIA) for our processing.
- Data Processing Agreement available on request.
- Public subprocessor list with purpose, location, and data categories.
- GDPR and CCPA aligned: consent withdrawal, data export, Do-Not-Sell, and Global Privacy Control honored.

## Protecting the people in your stories

The part of our posture specific to what Shine does: how the voices, words, and likenesses in customer stories are consented to, traced, and undone.

- Consent is dated and comes first: interviewees verify their email and agree, in plain language, to recording and marketing use before recording begins, stored with the date and time given.
- Provenance: published claims are extracted from the recorded interview and pinned to where they were said, with a grounding score so a paraphrase is never shown as a direct quote.
- Revocation propagates: withdrawing consent or unverifying a claim automatically suspends every Shine-hosted asset built on it, because each stays linked to its source claims. Anything already published outside Shine, like a review the customer posted or a video on their own channel, isn't ours to pull down, so we flag it for takedown and tell you exactly what to remove.
- Permanence: verifications, edits, and deletions are written to an append-only history (who and when) that outlives the claim; deletions are recoverable for 30 days before they are permanent.

## Reporting a vulnerability

If you believe you have found a security issue, we want to hear from you. Email hello@shine.studio with the subject "Security vulnerability report" and we will acknowledge within two business days and keep you updated as we investigate. We do not pursue researchers who report in good faith and give us a reasonable chance to resolve an issue before it is disclosed.

## Request security documentation

Need our documentation for a vendor review? Request our security package and we will send our security questionnaire, Data Processing Agreement, and subprocessor list within one business day. Email hello@shine.studio or use the request form at /security.
