Skip to content
Trust Center

Security is reviewable before you sign, not after

No client logos, no client names — that constraint is published as a security control, not hidden as an absence. This page is the substitute: an answer-first summary of what a security review actually asks for, plus a gated pack of the full documents.

Answer first

What a security review actually asks

Do you hold ISO 27001?

Yes, confirmed by the company. Certificate number, issuing body, scope and expiry are being compiled for publication — request them directly until this page carries the full record.

Do you hold a SOC 2 report?

Yes, confirmed by the company. SOC 2 is an attestation report rather than a certification, and it is shared under NDA rather than displayed as a badge. Request the report type and audit period on a call.

Is there a Data Processing Agreement?

Yes. A DPA incorporating standard contractual clauses is available and is signed before any personal data is processed under an engagement.

Who are your sub-processors?

Listed on the sub-processors page, kept current, with advance notice of any change. See /security-and-compliance/sub-processors.

How is data encrypted?

In transit via TLS 1.2 or higher on every connection. At rest via the storage-level encryption provided by our infrastructure vendors.

How is access controlled?

Named accounts only, never shared logins. Access is scoped to the engagement and role, multi-factor authentication is required, and access is reviewed on a defined schedule and revoked on offboarding.

What is your incident response process?

A documented process covering detection, containment, client notification and post-incident review.

What is your data retention policy?

Client data is retained only for the engagement’s duration plus any period you require for your own compliance, then deleted or returned per the data processing agreement.

Can we run our own security questionnaire or audit?

Yes. Security questionnaires are answered as part of scoping for any engagement handling sensitive data, and the specimen document pack can be requested before you commit to anything.

Certification records

Held, verified, or pending publication — stated plainly

A certification only ever renders here once its number, issuing body, scope and expiry are all confirmed. SOC 2 is an attestation report, not a certification, and is never shown as a badge.

ISO/IEC 27001 — Information Security Management

Held by the company. Certificate number, issuing body, scope and expiry are being compiled for publication.

SOC 2

Report available under NDA. Request the report type and audit period via the document pack below.

GDPR — Data Processing Agreement

A DPA incorporating standard contractual clauses, signed before any personal data is processed under an engagement. Available on request, and included in the document pack.

Controls

How access and data are actually handled

Access control

Named, individually attributable accounts for every system touching client data. No shared logins, no generic team credentials. Role-based access scoped to what the engagement actually requires.

Authentication

Multi-factor authentication required on every account with access to client systems or data, without exception for seniority.

Device and workstation policy

Client data is not stored on local devices. Clean-desk policy, no removable media, and screen-lock enforced on idle.

Network and endpoint

Managed endpoints, monitored network access, and segmentation between client accounts where the engagement requires it.

Confidentiality

Every employee signs a confidentiality agreement on their first day, covering all client information regardless of which account they are assigned to.

Vendor and sub-processor management

Sub-processors are assessed before use, listed publicly, and clients are notified in advance of any change.

Business continuity

A documented business continuity plan covering connectivity loss, facility disruption and key-person absence.

Independent attestation

Information security practices are independently assessed rather than self-certified — see the certification records above.

Request the full document pack

  • Information security policy summary
  • ISO 27001 certificate (once published)
  • SOC 2 report (once published, under NDA)
  • Data processing agreement template
  • Sub-processor list
  • Incident response summary
  • Sample security questionnaire responses
Request documents

Sub-processors

Every third party that could touch client data on our behalf, kept current, with advance notice of any change.

View the sub-processor list
Also asked

Related questions from the canonical FAQ

Will your team be available during our business hours?

Yes. Shifts are aligned to US Eastern, US Pacific or UK business hours as required, not to Indian Standard Time. The coverage page shows the actual shift mapping rather than a vague "24/7" claim.

Can we speak to your references?

Client identities are protected under NDA, so we do not publish names or logos. Two client references are available within three business days of a signed mutual NDA — a stated process with a turnaround, not just a stated willingness.

Where is our data stored?

Work happens inside your own systems wherever possible — your helpdesk, your accounting platform, your CRM, your repository. Where Shoora-operated tooling is used, storage location and sub-processors are listed on the Security & Compliance page.

Get started

Running a formal security review?

Request the document pack, or bring your questionnaire straight to a scoping call — we'd rather answer it live than make you wait on email.