Compliance and assurance status

Controlled-preview status: framework mappings are product work, not certifications or audit conclusions.

Controlled-preview documentation

Shielda is not generally available. Source code, fixtures, tests, version labels, plans, and historical checklists do not establish live availability, compatibility, compliance, or contract terms.

CONTROLLED PREVIEW — NO CERTIFICATION CLAIM. Shielda does not currently publish a SOC 2 or ISO certification, a clean external penetration-test report, a production availability assurance package, or evidence that use of Shielda makes a customer compliant.

What the product may assist with

Shielda's source contains work for organizing technical evidence, findings, control mappings, questionnaires, and reviewable remediation. Those implementation surfaces may support a scoped evaluation. A framework label, evaluator, template, generated document, or percentage in source is not an auditor opinion and does not establish operating effectiveness.

Deployment-specific data handling

The evaluated workflow must document which data enters the system, what remains in the customer environment, what leaves it, which providers process it, where it is stored, how long it is retained, and how export and deletion work. Shielda makes no blanket local-only, regional-hosting, zero-retention, or provider-training claim.

Evidence required for a stronger assurance claim

  • the exact release and deployment in scope;
  • a current control owner and approved control description;
  • live operating evidence for the stated period;
  • limitations, exceptions, and unresolved gaps;
  • independent review or audit where the claim requires it;
  • permission to share any customer or third-party material.

Current documents

The public privacy status, terms status, draft DPA status, and draft subprocessor status state their current boundaries. None should be read as an executed agreement or certification.