Compliance ·

Security and Confidentiality for Professionals

A plain account of how ShieldFive supports professional confidentiality, GDPR, and GLBA obligations — and, just as plainly, where its limits are: no external audit yet, no SOC 2, no BAA.

ShieldFive is built for people who are professionally responsible for other people's confidential files — accountants, financial advisors, and legal teams. This page explains, plainly, how the product supports that responsibility, and where its limits are.

Client-side encryption and its trust boundary

Files are encrypted on your device before upload. Your password never reaches our servers: the browser turns it into a separate login value with Argon2id and sends only that, and the key that opens your vault is derived separately and stays on your device. The app code is delivered by ShieldFive, so the client you are served is part of the trust boundary: client-side encryption does not establish that ShieldFive is technically unable to decrypt your files. See the security overview before deciding whether this model meets your requirements.

Web uploads default to the ML-KEM-1024/XChaCha20-Poly1305 hybrid format, with an AES-256-GCM fallback. Android also writes the hybrid format by default, with the same AES-256-GCM fallback, and reads both formats. The format used by a particular client matters; we do not promise post-quantum hybrid encryption for every upload.

Controls that support your obligations

ShieldFive is designed to help you meet your professional confidentiality, GDPR, and GLBA / FTC Safeguards obligations when you handle client data:

  • End-to-end encryption in transit and at rest, with client-side, on-device key generation.
  • Secure share links with expiry dates, download limits, and passphrase protection (Argon2id).
  • EU data residency: encrypted data is stored in the EU, under EU jurisdiction.
  • The Article 28 Data Processing Agreement is published at /privacy/dpa and included on every seat — not gated behind an enterprise tier. Its terms apply unchanged; email [email protected] to have a copy executed for your organisation.

ShieldFive supports these obligations; it does not discharge them. Compliance remains the professional's responsibility, and this page is neither a certification nor a legal opinion.

Transparency instead of a certificate

We have not yet purchased a third-party audit, so instead we let you verify us directly:

  • Open-source cryptography. Our crypto library, @shieldfive/crypto, is public under Apache-2.0, so you can read the exact code that encrypts your files.
  • A published internal security review: 31 findings (0 critical, 0 high, 7 medium, 17 low, 7 informational), 26 of them fixed.

What we do not claim

Plain limits, so you can trust what we do claim:

  • No completed third-party or external security audit yet.
  • No SOC 2 or ISO 27001 certification.
  • The cryptography library is open source; the web and mobile applications themselves are closed source.
  • No US HIPAA Business Associate Agreement — HIPAA governs health data, which is outside an accounting or legal document workflow.

If your firm requires a completed external audit or a signed BAA today, ShieldFive is not the right fit yet — and we would rather tell you that here than in a sales call.

Frequently asked questions

Is ShieldFive GLBA compliant?
Using ShieldFive does not establish GLBA compliance for your business. ShieldFive encrypts files on the device and stores encrypted file data in the EU. Your password never reaches our servers: the browser turns it into a separate login value with Argon2id and sends only that, and the key that opens the vault is derived separately and stays on the device. The app code is delivered by us, so the client you are served on each visit remains part of the trust boundary. This is not an absolute provider-cannot-decrypt guarantee.
Does ShieldFive offer a HIPAA Business Associate Agreement (BAA)?
No. ShieldFive does not offer a US HIPAA Business Associate Agreement.
Is ShieldFive SOC 2 certified or independently audited?
Not yet. ShieldFive has not completed a SOC 2 certification or a third-party security audit. Instead, its cryptography library is open source and a full internal security review is published for you to inspect.
Can a business customer get a Data Processing Agreement (DPA)?
Yes. The Article 28 Data Processing Agreement is published at /privacy/dpa and is included on every seat — not gated behind an enterprise tier. Its terms apply unchanged; email [email protected] to have a copy executed for your organisation.
Where is client data stored?
ShieldFive encrypts files on the device and stores encrypted file data in the EU. Your password never reaches our servers: the browser turns it into a separate login value with Argon2id and sends only that, and the key that opens the vault is derived separately and stays on the device. The app code is delivered by us, so the client you are served on each visit remains part of the trust boundary. This is not an absolute provider-cannot-decrypt guarantee.

Ready to Protect What's Yours?

Encrypted on your device

5 GB free · No card required · Encrypted before upload