Compliance posture
Where iShared.app stands today on formal certifications, and what's on the roadmap - stated plainly rather than implied.
We'd rather tell you plainly where things stand than let a badge on a page imply more than is true.
Where we are today
iShared.app is not currently SOC 2 or ISO 27001 certified. We follow a number of practices that align with what those frameworks expect - encryption in transit and at rest, role-based access control, MFA and SSO, audit logging of account and organization changes, and rate-limited authentication - documented on our security page. Following good practices isn't the same thing as an independent audit, and we won't describe it as one.
GDPR and UK data protection
- Our Privacy Policy describes what personal data we collect and why.
- Our Cookie Policy covers cookies and similar technologies, with a consent banner that respects your choice.
- Application data and file storage are currently held in AWS's London (eu-west-2) region.
- If your organization needs a signed Data Processing Agreement, see data processing.
What's on the roadmap
- A formal SOC 2 Type II audit, once the underlying infrastructure work it depends on (documented backups, monitoring, and change-management process) is in place.
- A public sub-processor change notification process.
- Configurable data residency for Enterprise customers with a specific regional requirement.
Questions from your security team
If you're evaluating iShared.app for your organization and have a security questionnaire, contact sales - we're glad to work through it directly rather than you guessing at answers from this page.