TRUST & SECURITY
Security at ShieldX
ShieldX processes decision-critical data for financial institutions. Security is infrastructure — not a feature.
DPDP Act AlignedISO 27001 In ProgressAES-256 EncryptionTLS 1.2+ In Transit
DATA PROTECTION
DPDP Act, 2023 aligned
Our data handling practices are designed to align with the Digital Personal Data Protection Act, 2023. Purpose limitation, data minimisation, and consent management are built into our processing workflows — not bolted on after the fact.
CERTIFICATION
ISO 27001 certification in progress
We are actively working towards ISO/IEC 27001:2022 certification for our information security management system. Controls across access management, incident response, vulnerability management, and business continuity are being implemented and documented.
ACCESS CONTROL
Least-privilege access architecture
Role-based access controls are enforced across all internal systems. Engineers access only what their role requires. Access reviews are conducted periodically. No standing privileged access to production environments.
ENCRYPTION
Encryption at rest and in transit
All data is encrypted at rest using AES-256. All data in transit is protected using TLS 1.2 or higher. Keys are managed through dedicated key management infrastructure and rotated regularly.
AUDIT
Immutable audit infrastructure
Every decision, access event, and configuration change is logged to an immutable audit trail. Logs cannot be altered or deleted by application-layer operations. Exportable for regulatory review on demand.
INCIDENT RESPONSE
Incident detection and response
We maintain a documented incident response plan covering detection, containment, investigation, and notification. Security events are monitored continuously. Affected parties are notified within timelines required under applicable Indian regulations.
SECURITY PRACTICES
What we do, not just what we claim.
✓Secure development lifecycle with mandatory code review
✓Dependency vulnerability scanning on every build
✓Regular penetration testing by third-party security firms
✓No customer production data used in development or test environments
✓Vendor security assessment before onboarding third-party processors
✓Business continuity and disaster recovery plans maintained and tested
✓Employee security awareness training conducted regularly
✓Sensitive credentials managed through secrets management tooling — never hardcoded
Security disclosure
If you believe you have found a security vulnerability in ShieldX, please report it responsibly to our security team. We commit to acknowledging your report within 48 hours and working with you on a resolution timeline.
Contact: security@queloai.online
