Trust & Security
Last updated: July 23, 2026
Shredr processes documents and connects to business systems on behalf of our customers, so protecting that data is core to what we do. This page summarizes the security practices behind the Shredr platform. For detailed documentation, see requesting documentation below.
Our security program
Encryption
Customer data is encrypted in transit with TLS and at rest using AWS KMS-managed keys. Credentials for connected client databases are encrypted at the application layer before storage.
Multi-tenant isolation
Data is scoped by tenant. Analytical access is enforced in the database with PostgreSQL Row-Level Security and a dedicated read-only role, so one tenant's queries cannot reach another tenant's data.
Access control
Access follows least privilege. Application access uses session-based authentication, the admin interface is restricted to authorized staff, and infrastructure access is governed by scoped IAM roles with deployments via short-lived OIDC credentials.
Network security
The platform runs in an isolated AWS VPC with private subnets, containers behind a load balancer, and an AWS WAF filtering traffic to the API.
Secure development
Every change is peer-reviewed before release, developed test-first, and validated by automated linting, type checks, and tests in continuous integration.
Monitoring & incident response
Application errors, infrastructure logs, and anomalies are monitored continuously. We maintain a documented incident response process with defined severity tiers and customer notification procedures.
Vulnerability management
Dependencies are scanned continuously with automated tooling, and findings are triaged and remediated against severity-based service-level targets.
Data privacy & retention
We process personal data in line with our Privacy Policy, support data deletion requests, and let workspaces configure document-data retention.
Compliance & certifications
Shredr maintains a documented information security program, incident response process, and vulnerability management policy. A SOC 2 examination is planned for the upcoming fiscal year. We are happy to share supporting documentation with customers and prospects under a mutual non-disclosure agreement.
Subprocessors
Shredr uses a small number of vetted third-party subprocessors to operate the platform. See our subprocessor list for details.
Data privacy & your rights
Our Privacy Policy explains what data we process and your rights over it, including access and deletion. To exercise those rights or request account deletion, contact support@shredr.ai. Data Processing Agreements are available for customers that require them.
Request documentation or report an issue
To request our security documentation, a Data Processing Agreement, or to report a suspected vulnerability, contact support@shredr.ai. We investigate all good-faith reports and respond promptly.