How does Shellvoide handle client engagement data?
Client data is stored in an isolated workspace restricted to named testers, encrypted in transit and at rest. Hands-on engagements run in isolated, ephemeral environments destroyed on completion. No client data is used to train our models or shared across engagements. See the Engagement & Data Handling page for the full lifecycle.
Who at Shellvoide has access to my findings?
Only the named testers assigned to your engagement can access that engagement's data. There is no broad internal access. All access is authenticated, logged, and attributable to an individual.
How long is my data retained after an engagement?
Engagement artifacts are retained in your workspace until you delete them or the retention period ends. Ephemeral sandbox environments are destroyed on completion. See the Data Retention Policy for specifics.
Can I request early deletion of my data?
Yes. You can request export or deletion at any time, subject to legal retention obligations. Contact disclosure@shellvoide.com.
KLUE platform
Where is KLUE data stored?
Customer scan content and findings are stored in the region configured for the tenant, in cloud-hosted database and object storage with per-tenant row-level security.
Is my data used to train KLUE's models?
No. Client data is never used to train our models. Training controls enabled where available. For sensitive workloads, models can run so data never leaves a controlled environment.
Does KLUE support SSO?
Yes. SSO/SAML and MFA are available for KLUE customers.
How is each scan isolated?
Every scan runs inside an isolated, ephemeral virtual machine. Source code is cloned using short-lived tokens scrubbed after use. The sandbox is destroyed when the scan finishes.
Engagements & legal
Do you sign NDAs?
Yes. A mutual NDA is signed before any sensitive data is exchanged, and engagement-specific scoping is always documented.
Can you sign our DPA?
Yes. A Data Processing Agreement is available on request at disclosure@shellvoide.com.
What certifications does Shellvoide hold?
Shellvoide is ISO/IEC 27001:2022 certified, compliant with GDPR, and aligned with NIST CSF. PCI DSS is fully outsourced to our payment processor. You can request a copy of our certificate from the Resources section on the Overview page.
How do I report a vulnerability?
Email disclosure@shellvoide.com with a description, steps to reproduce, and the affected asset. We acknowledge within 2 business days and coordinate disclosure after a fix.