Security is reviewable before you sign, not after
No client logos, no client names — that constraint is published as a security control, not hidden as an absence. This page is the substitute: an answer-first summary of what a security review actually asks for, plus a gated pack of the full documents.
What a security review actually asks
Do you hold ISO 27001?
Yes, confirmed by the company. Certificate number, issuing body, scope and expiry are being compiled for publication — request them directly until this page carries the full record.
Do you hold a SOC 2 report?
Yes, confirmed by the company. SOC 2 is an attestation report rather than a certification, and it is shared under NDA rather than displayed as a badge. Request the report type and audit period on a call.
Is there a Data Processing Agreement?
Yes. A DPA incorporating standard contractual clauses is available and is signed before any personal data is processed under an engagement.
Who are your sub-processors?
Listed on the sub-processors page, kept current, with advance notice of any change. See /security-and-compliance/sub-processors.
How is data encrypted?
In transit via TLS 1.2 or higher on every connection. At rest via the storage-level encryption provided by our infrastructure vendors.
How is access controlled?
Named accounts only, never shared logins. Access is scoped to the engagement and role, multi-factor authentication is required, and access is reviewed on a defined schedule and revoked on offboarding.
What is your incident response process?
A documented process covering detection, containment, client notification and post-incident review.
What is your data retention policy?
Client data is retained only for the engagement’s duration plus any period you require for your own compliance, then deleted or returned per the data processing agreement.
Can we run our own security questionnaire or audit?
Yes. Security questionnaires are answered as part of scoping for any engagement handling sensitive data, and the specimen document pack can be requested before you commit to anything.
Held, verified, or pending publication — stated plainly
A certification only ever renders here once its number, issuing body, scope and expiry are all confirmed. SOC 2 is an attestation report, not a certification, and is never shown as a badge.
ISO/IEC 27001 — Information Security Management
Held by the company. Certificate number, issuing body, scope and expiry are being compiled for publication.
SOC 2
Report available under NDA. Request the report type and audit period via the document pack below.
GDPR — Data Processing Agreement
A DPA incorporating standard contractual clauses, signed before any personal data is processed under an engagement. Available on request, and included in the document pack.
How access and data are actually handled
Access control
Named, individually attributable accounts for every system touching client data. No shared logins, no generic team credentials. Role-based access scoped to what the engagement actually requires.
Authentication
Multi-factor authentication required on every account with access to client systems or data, without exception for seniority.
Device and workstation policy
Client data is not stored on local devices. Clean-desk policy, no removable media, and screen-lock enforced on idle.
Network and endpoint
Managed endpoints, monitored network access, and segmentation between client accounts where the engagement requires it.
Confidentiality
Every employee signs a confidentiality agreement on their first day, covering all client information regardless of which account they are assigned to.
Vendor and sub-processor management
Sub-processors are assessed before use, listed publicly, and clients are notified in advance of any change.
Business continuity
A documented business continuity plan covering connectivity loss, facility disruption and key-person absence.
Independent attestation
Information security practices are independently assessed rather than self-certified — see the certification records above.
Request the full document pack
- Information security policy summary
- ISO 27001 certificate (once published)
- SOC 2 report (once published, under NDA)
- Data processing agreement template
- Sub-processor list
- Incident response summary
- Sample security questionnaire responses
Sub-processors
Every third party that could touch client data on our behalf, kept current, with advance notice of any change.
View the sub-processor listRelated questions from the canonical FAQ
Will your team be available during our business hours?
Yes. Shifts are aligned to US Eastern, US Pacific or UK business hours as required, not to Indian Standard Time. The coverage page shows the actual shift mapping rather than a vague "24/7" claim.
Can we speak to your references?
Client identities are protected under NDA, so we do not publish names or logos. Two client references are available within three business days of a signed mutual NDA — a stated process with a turnaround, not just a stated willingness.
Where is our data stored?
Work happens inside your own systems wherever possible — your helpdesk, your accounting platform, your CRM, your repository. Where Shoora-operated tooling is used, storage location and sub-processors are listed on the Security & Compliance page.
