Built to handle the documents you can't afford to leak
ChitiShield processes sensitive policy and compliance documents. Here's how we protect them.
Encryption in transit and at rest
All traffic to ChitiShield is encrypted via TLS 1.2+. Uploaded documents and account data are encrypted at rest.
Least-privilege access
Internal access to customer documents is role-restricted and logged. Engineers do not have standing access to production data.
India-region hosting
Customer data is hosted on infrastructure in India-based regions, with backups encrypted and access-controlled.
Document retention controls
You control how long uploaded documents are retained. Deletion requests are honored within 30 days.
Audit logging
Key account and document actions are logged, so you can see who accessed what and when.
Responsible disclosure
Found a security issue? We welcome reports at security@chitishield.com and will respond within 2 business days.
Compliance certifications
ChitiShield is currently pursuing SOC 2 Type II and ISO 27001 certification as the company scales. We’ll publish audit reports here as they become available. In the meantime, our security practices above reflect our current operating standard.
Reporting a vulnerability
If you believe you’ve found a security vulnerability in ChitiShield, please email security@chitishield.com with details. We ask that you give us a reasonable window to investigate and patch before public disclosure.