Data Security
Last Updated: July 26, 2026
Shield Spire Ops is designed as an enterprise-grade, multi-tenant operational platform for organizations operating in security, compliance-driven, and multi-site environments. The platform architecture prioritizes data isolation, controlled access, auditability, and operational integrity.
This page provides an overview of how security is implemented within the platform.
1.Security Architecture Overview
Shield Spire Ops is built on a layered security model that combines:
- multi-tenant data isolation
- role-based access control (RBAC)
- row-level security (RLS) enforcement
- secure authentication mechanisms
- audit logging and traceability
- controlled API access
- mobile and field security protections
As of the date above, the platform architecture includes:
- 1,265 Row-Level Security policies
- 450 public database tables
- 808 database functions and remote procedure calls
- 166 Edge Functions
- 1,042 database migrations
- 19 role definitions across 5 primary role-based portals
- a public REST API (v1) with scoped keys and rate limiting
These figures describe the current implementation and may change as the platform evolves. They are provided for transparency and do not constitute a warranty or a guarantee of security outcomes.
2.Core Security Pillars
Multi-Tenant Data Isolation
Each organization operates in a logically isolated environment. Data is segmented by tenant boundaries, preventing unauthorized cross-tenant access.
Role-Based Access Control (RBAC)
User access is restricted based on role, ensuring individuals only see and interact with data relevant to their responsibilities.
Row-Level Security (RLS)
Fine-grained database-level policies enforce access rules at the data level, providing an additional layer of protection beyond application logic.
Authentication & MFA
Secure login systems, including optional multi-factor authentication (MFA), protect account access and reduce risk of unauthorized entry.
Audit Logging & Traceability
All critical actions are logged, including user activity, administrative changes, and operational events. This enables full traceability and accountability.
Session & Access Control
Session lifecycle management includes expiration, refresh, and monitoring of active sessions to reduce exposure risk.
Mobile & Field Security
Mobile workflows are secured through session validation, device-aware controls, and protected communication channels.
API Security & Access Governance
API access is controlled through scoped keys, rate limiting, IP restrictions, and monitored usage patterns.
3.Access Control & Identity Management
Access to the platform is controlled through multiple layers:
- user authentication (login credentials + MFA where enabled)
- role assignment (Admin, Employee, Client, Applicant, Platform Owner)
- tenant-scoped visibility
- module-level permissions
- controlled access to sensitive data
Examples include:
- employees accessing only their own records
- supervisors accessing team-level data
- clients accessing limited client-facing dashboards
- platform owner access controlled through context-switch mechanisms
4.Data Protection and Storage
Shield Spire Ops implements controls to protect data both in transit and at rest.
These include:
- encryption in transit using TLS (HTTPS)
- encryption at rest within the managed database and storage layer
- controlled storage environments
- restricted access to sensitive records
- secure handling of uploaded documents and media
- separation of tenant data within the database architecture
5.Audit, Monitoring, and Accountability
The platform maintains comprehensive audit capabilities, including:
- user activity tracking
- login and session logs
- administrative actions
- role changes
- compliance review actions
- API usage logs
- system events and operational logs
These logs support:
- internal accountability
- tenant oversight
- audit preparation
- SLA tracking
- incident investigation
6.Compliance-Oriented Security Design
Shield Spire Ops is designed to support organizations operating in regulated environments.
Security features are aligned with:
- compliance workflows
- document verification processes
- expiration monitoring
- training enforcement systems
- audit-ready reporting
7.Mobile and Field Security
For field operations, the platform enforces:
- secure session validation on mobile devices
- GPS-based verification tied to user sessions and enabled operational actions
- controlled media capture workflows
- secure device storage for authentication material
- device-security signals, including detection of rooted or jailbroken devices
- device-level communication safeguards
These protections are intended to keep field data:
- attributable
- verifiable
- securely transmitted
Mobile workflows generally require an active internet or mobile data connection. Offline field capabilities remain under development and are not generally available. Emergency dispatch actions are intentionally blocked without connectivity for safety reasons.
8.Integration and Infrastructure Security
Shield Spire Ops integrates with infrastructure and service providers to support platform functionality.
Security considerations include:
- controlled API communication
- scoped API keys and per-key permissions
- API rate limiting
- webhook validation
- service-level authentication
- separation between platform and tenant financial flows (e.g., Stripe Connect)
Third-party providers are selected to support reliability and security but operate under their own policies.
9.AI Governance and Controls
Where AI-assisted functionality is enabled, Shield Spire Ops applies dedicated governance controls, including:
- global platform-level enablement and disablement of AI capabilities
- tenant-level AI configuration and feature controls
- AI usage auditing and request records
- daily AI spending limits
- fail-closed behavior in governed capabilities, so that a control failure denies rather than permits access
- additional opt-in and redaction controls for sensitive form workflows
AI assistance is advisory and Human-in-the-Loop. Further detail is provided in the Shield AI Usage and Transparency Policy.
10.Certifications and Independent Assurance
Shield Spire Ops implements substantial technical and organizational security controls. However, we do not currently claim, and this page should not be read as claiming, any of the following:
- SOC 2 attestation
- ISO/IEC 27001 certification
- HIPAA certification
- PCI DSS certification of the platform
- FedRAMP authorization
- independent third-party security audit or penetration-test certification
No system can be made completely secure. We do not represent that the platform is immune to compromise, and we do not guarantee the prevention of all security incidents. Where a customer requires formal assurance documentation, that must be addressed through a separate written agreement.
11.Shared Responsibility Model
Security within Shield Spire Ops follows a shared responsibility model:
Platform Responsibilities
- infrastructure security
- access control systems
- platform-level protections
- audit logging
Tenant Responsibilities
- user management
- credential protection
- correct role assignment
- compliance with applicable laws
- proper operational use of the platform
12.Continuous Improvement
Security is continuously reviewed and improved through:
- system monitoring
- feature updates
- security enhancements
- architecture refinements
We evolve the platform to address emerging risks and operational requirements.
13.Contact Information
For security-related inquiries:
Shield Spire Ops operates as part of the GEEC AI Platform ecosystem.