Security & trust
You shouldn’t have to take a security policy on faith. WeShield’s protections are built into the database itself, so they hold the same way for every organization, in every region — and you can check them.
Enforced, not promised
Whether a request comes from a person or the AI, it takes the same checked route. The gold step — a person approving anything irreversible — is built into the database, so the AI can’t skip it.
from a person or an AI agent
authorized · rate-limited · recorded
walled off by forced row-level security
required for anything irreversible
and the record shows who, when, why
Every step writes to the hash-chained audit. AI requests detour first through a redactor that strips personal details before anything reaches a model.
Control by control
Each of these is built and live — not a roadmap item. The mechanism is named so you can check it.
AI drafts, scores, and suggests — but sending, publishing, and connecting need a person. AI agents are blocked at the database from those actions; they can’t do them even with direct access.
Forced row-level security on every table — even a privileged connection can’t read across workspaces; the database itself says no. Proven in CI on real Postgres, not just simulated.
Every change goes through one audited path and lands on a per-workspace, hash-chained log. Alter or delete a single row and the break is visible — to you, and to an auditor.
Personal details — email, phone, card, government ID — are stripped before any prompt leaves. Spend is metered with a hard ceiling, a kill-switch, and a velocity brake. Every call is on the record.
You choose where your data lives — today’s default is Montréal (ca-central-1), and the live status page reports the serving region. AI inference is opt-in, receives only redacted text, and a restricted workspace is never routed outside its region.
Export your whole workspace whenever you want, in formats you can use, with the audit trail intact — and request full erasure through a secure, recorded path.
Standards
We map our controls to SOC 2, ISO 27001, ISO 42001, NIST AI RMF, and PIPEDA — and we don’t display a certification we haven’t earned. Here’s exactly where we stand.
Our terms, privacy practices, data-processing agreement, and the sub-processors we rely on — including the AI provider, named.
Found something? Responsible disclosure: security@weshield.ai