Audit-Ready Infrastructure

Data Security

Last Updated: July 26, 2026

Shield Spire Ops is designed as an enterprise-grade, multi-tenant operational platform for organizations operating in security, compliance-driven, and multi-site environments. The platform architecture prioritizes data isolation, controlled access, auditability, and operational integrity.

This page provides an overview of how security is implemented within the platform.

1.Security Architecture Overview

Shield Spire Ops is built on a layered security model that combines:

  • multi-tenant data isolation
  • role-based access control (RBAC)
  • row-level security (RLS) enforcement
  • secure authentication mechanisms
  • audit logging and traceability
  • controlled API access
  • mobile and field security protections

As of the date above, the platform architecture includes:

  • 1,265 Row-Level Security policies
  • 450 public database tables
  • 808 database functions and remote procedure calls
  • 166 Edge Functions
  • 1,042 database migrations
  • 19 role definitions across 5 primary role-based portals
  • a public REST API (v1) with scoped keys and rate limiting

These figures describe the current implementation and may change as the platform evolves. They are provided for transparency and do not constitute a warranty or a guarantee of security outcomes.

Security is not treated as a single feature, but as a system-wide design principle embedded across all workflows.

2.Core Security Pillars

Multi-Tenant Data Isolation

Each organization operates in a logically isolated environment. Data is segmented by tenant boundaries, preventing unauthorized cross-tenant access.

Role-Based Access Control (RBAC)

User access is restricted based on role, ensuring individuals only see and interact with data relevant to their responsibilities.

Row-Level Security (RLS)

Fine-grained database-level policies enforce access rules at the data level, providing an additional layer of protection beyond application logic.

Authentication & MFA

Secure login systems, including optional multi-factor authentication (MFA), protect account access and reduce risk of unauthorized entry.

Audit Logging & Traceability

All critical actions are logged, including user activity, administrative changes, and operational events. This enables full traceability and accountability.

Session & Access Control

Session lifecycle management includes expiration, refresh, and monitoring of active sessions to reduce exposure risk.

Mobile & Field Security

Mobile workflows are secured through session validation, device-aware controls, and protected communication channels.

API Security & Access Governance

API access is controlled through scoped keys, rate limiting, IP restrictions, and monitored usage patterns.

3.Access Control & Identity Management

Access to the platform is controlled through multiple layers:

  • user authentication (login credentials + MFA where enabled)
  • role assignment (Admin, Employee, Client, Applicant, Platform Owner)
  • tenant-scoped visibility
  • module-level permissions
  • controlled access to sensitive data

Examples include:

  • employees accessing only their own records
  • supervisors accessing team-level data
  • clients accessing limited client-facing dashboards
  • platform owner access controlled through context-switch mechanisms

4.Data Protection and Storage

Shield Spire Ops implements controls to protect data both in transit and at rest.

These include:

  • encryption in transit using TLS (HTTPS)
  • encryption at rest within the managed database and storage layer
  • controlled storage environments
  • restricted access to sensitive records
  • secure handling of uploaded documents and media
  • separation of tenant data within the database architecture
Sensitive data such as compliance documents, incident reports, and operational logs are handled within controlled access environments.

5.Audit, Monitoring, and Accountability

The platform maintains comprehensive audit capabilities, including:

  • user activity tracking
  • login and session logs
  • administrative actions
  • role changes
  • compliance review actions
  • API usage logs
  • system events and operational logs

These logs support:

  • internal accountability
  • tenant oversight
  • audit preparation
  • SLA tracking
  • incident investigation

6.Compliance-Oriented Security Design

Shield Spire Ops is designed to support organizations operating in regulated environments.

Security features are aligned with:

  • compliance workflows
  • document verification processes
  • expiration monitoring
  • training enforcement systems
  • audit-ready reporting
The platform enables structured compliance tracking but does not replace legal responsibility of the tenant.

7.Mobile and Field Security

For field operations, the platform enforces:

  • secure session validation on mobile devices
  • GPS-based verification tied to user sessions and enabled operational actions
  • controlled media capture workflows
  • secure device storage for authentication material
  • device-security signals, including detection of rooted or jailbroken devices
  • device-level communication safeguards

These protections are intended to keep field data:

  • attributable
  • verifiable
  • securely transmitted

Mobile workflows generally require an active internet or mobile data connection. Offline field capabilities remain under development and are not generally available. Emergency dispatch actions are intentionally blocked without connectivity for safety reasons.

8.Integration and Infrastructure Security

Shield Spire Ops integrates with infrastructure and service providers to support platform functionality.

Security considerations include:

  • controlled API communication
  • scoped API keys and per-key permissions
  • API rate limiting
  • webhook validation
  • service-level authentication
  • separation between platform and tenant financial flows (e.g., Stripe Connect)

Third-party providers are selected to support reliability and security but operate under their own policies.

9.AI Governance and Controls

Where AI-assisted functionality is enabled, Shield Spire Ops applies dedicated governance controls, including:

  • global platform-level enablement and disablement of AI capabilities
  • tenant-level AI configuration and feature controls
  • AI usage auditing and request records
  • daily AI spending limits
  • fail-closed behavior in governed capabilities, so that a control failure denies rather than permits access
  • additional opt-in and redaction controls for sensitive form workflows

AI assistance is advisory and Human-in-the-Loop. Further detail is provided in the Shield AI Usage and Transparency Policy.

10.Certifications and Independent Assurance

Shield Spire Ops implements substantial technical and organizational security controls. However, we do not currently claim, and this page should not be read as claiming, any of the following:

  • SOC 2 attestation
  • ISO/IEC 27001 certification
  • HIPAA certification
  • PCI DSS certification of the platform
  • FedRAMP authorization
  • independent third-party security audit or penetration-test certification

No system can be made completely secure. We do not represent that the platform is immune to compromise, and we do not guarantee the prevention of all security incidents. Where a customer requires formal assurance documentation, that must be addressed through a separate written agreement.

11.Shared Responsibility Model

Security within Shield Spire Ops follows a shared responsibility model:

Platform Responsibilities

  • infrastructure security
  • access control systems
  • platform-level protections
  • audit logging

Tenant Responsibilities

  • user management
  • credential protection
  • correct role assignment
  • compliance with applicable laws
  • proper operational use of the platform

12.Continuous Improvement

Security is continuously reviewed and improved through:

  • system monitoring
  • feature updates
  • security enhancements
  • architecture refinements

We evolve the platform to address emerging risks and operational requirements.

13.Contact Information

For security-related inquiries:

Shield Spire Ops operates as part of the GEEC AI Platform ecosystem.