Shortlist
Security & Compliance

Enterprise-grade security for your vendor decisions

Every layer of Shortlist is designed with security, privacy, and compliance as foundational requirements — not afterthoughts.

Certifications & Standards

TLS 1.3 Active

All data encrypted in transit

AES-256 Active

Data encrypted at rest

💳
PCI DSS Level 1 Active

Via Stripe certified processor

🇪🇺
GDPR Compliant Active

Full data subject rights support

SOC 2 Type I In Progress

Audit in progress — Q3 2026

ISO 27001 Planned

Planned for 2027

01

Data Encryption

Your data is encrypted at every stage of its lifecycle.

  • AES-256 encryption at rest via Supabase managed PostgreSQL
  • TLS 1.3 encryption for all data in transit
  • API keys are SHA-256 hashed before storage — plaintext never persisted
  • Webhook payloads signed with HMAC-SHA256 (Svix-compatible)
02

Access Control

Fine-grained permissions at every layer of the platform.

  • Row-Level Security (RLS) on all database tables — data isolation per organization
  • 5-tier role hierarchy: Owner, Admin, Leadership, Member, Viewer
  • API key scopes: read, write, admin — each endpoint enforces minimum scope
  • SAML 2.0 SSO with enforced mode (enterprise tier) — Okta, Azure AD, Google Workspace
  • CSRF protection on all mutating endpoints
03

Infrastructure

Built on proven, managed infrastructure.

  • Supabase managed PostgreSQL with automatic backups and point-in-time recovery
  • Vercel edge deployment — global CDN, automatic failover
  • Two-layer rate limiting: IP-based DDoS shield + per-key plan-tiered limits
  • Security headers: CSP, HSTS, X-Frame-Options, X-Content-Type-Options
  • Sentry error monitoring with PII scrubbing
04

Privacy & Data Governance

Your data stays yours. We take privacy seriously.

  • GDPR-compliant data handling with right to erasure, portability, and access
  • CCPA-compliant opt-out and data deletion support
  • Differential privacy (ε=1.5) on all cross-organization analytics — true scores never leave PostgreSQL
  • Privacy budget tracking with quarterly epsilon limits per organization
  • Data retention policies enforced with automatic cleanup
  • EU AI Act Article 27 Fundamental Rights Impact Assessment completed
05

AI & Model Security

Our AI pipeline is designed with security-first principles.

  • Provider abstraction with Anthropic primary + OpenAI failover + circuit breaker
  • No customer data used for model training — all interactions are ephemeral
  • Bayesian confidence scoring with transparent thresholds (0.85/0.50/0.50)
  • Input sanitization on all AI prompts to prevent injection attacks
  • Audit logging on all AI-assisted decisions for compliance trails
06

Audit & Compliance

Every action is logged. Every decision is traceable.

  • Immutable event store for all decision actions (append-only with version control)
  • Organization-scoped audit logs with IP, user agent, and timestamp tracking
  • Comprehensive compliance documentation: FRIA, DPIA, and Data Retention Policy
  • Webhook event delivery with signed payloads for integration auditing
  • Export-ready audit trail for compliance teams

Compliance Documentation

We maintain comprehensive compliance documentation aligned with international regulatory frameworks.

Questions about security?

Our team is available to discuss specific security requirements, share our SOC 2 audit timeline, or provide additional documentation for your security review.