Skip to content
WeShieldWeShield
ProductsPricingSecurityAbout
Request access
WeShieldWeShield

The ecosystem for community safety and development — grants, a verified network, risk signals, and case management on one secure platform.

Data residency you control · ca-central-1 today

Product

  • All products
  • Pricing
  • Request access
  • Status

Company

  • About
  • Security
  • AI transparency
  • FAQ
  • Contact

Legal

  • Terms
  • Privacy
  • DPA
  • Subprocessors
© 2026 WeShield AI Inc.
Data residency you control · ca-central-1 today
Skip to content
WeShieldWeShield
ProductsPricingSecurityAbout
Request access

Security & trust

Trust you can verify.

You shouldn’t have to take a security policy on faith. WeShield’s protections are built into the database itself, so they hold the same way for every organization, in every region — and you can check them.

Enforced, not promised

Every action runs through one audited path.

Whether a request comes from a person or the AI, it takes the same checked route. The gold step — a person approving anything irreversible — is built into the database, so the AI can’t skip it.

  1. Request

    from a person or an AI agent

    →
  2. Audited gateway

    authorized · rate-limited · recorded

    →
  3. Your workspace

    walled off by forced row-level security

    →
  4. A person ratifies

    required for anything irreversible

    →
  5. It happens

    and the record shows who, when, why

Every step writes to the hash-chained audit. AI requests detour first through a redactor that strips personal details before anything reaches a model.

a person decidesEvery AI system, on the record→

Control by control

What that means, in plain terms.

Each of these is built and live — not a roadmap item. The mechanism is named so you can check it.

A person holds the pen

AI drafts, scores, and suggests — but sending, publishing, and connecting need a person. AI agents are blocked at the database from those actions; they can’t do them even with direct access.

Your workspace is yours alone

Forced row-level security on every table — even a privileged connection can’t read across workspaces; the database itself says no. Proven in CI on real Postgres, not just simulated.

A record you can check

Every change goes through one audited path and lands on a per-workspace, hash-chained log. Alter or delete a single row and the break is visible — to you, and to an auditor.

Scrubbed before the AI sees it

Personal details — email, phone, card, government ID — are stripped before any prompt leaves. Spend is metered with a hard ceiling, a kill-switch, and a velocity brake. Every call is on the record.

Data residency you control

You choose where your data lives — today’s default is Montréal (ca-central-1), and the live status page reports the serving region. AI inference is opt-in, receives only redacted text, and a restricted workspace is never routed outside its region.

Yours to take back

Export your whole workspace whenever you want, in formats you can use, with the audit trail intact — and request full erasure through a secure, recorded path.

Standards

Built to the standards’ principles. Honest about the audits.

We map our controls to SOC 2, ISO 27001, ISO 42001, NIST AI RMF, and PIPEDA — and we don’t display a certification we haven’t earned. Here’s exactly where we stand.

In place today

  • Forced row-level security, proven on real Postgres in CI
  • Per-workspace hash-chained, tamper-evident audit
  • Human-ratify enforced in the database (agents can’t send/publish/connect)
  • PII redaction before any AI call · metered spend · kill-switch
  • Export + permanent erasure (PIPEDA / Law 25 design)
  • No known vulnerabilities at last dependency scan · CycloneDX SBOM · PII-scrubbed monitoring

On the roadmap, named

  • SOC 2 Type II audit
  • Residency log backend + OpenTelemetry
  • DR drills + region-failure test
  • A stated SLA
  • Dedicated KMS subsystem
  • Entity-scoped authorization

The fine print, in full

Our terms, privacy practices, data-processing agreement, and the sub-processors we rely on — including the AI provider, named.

TermsPrivacyDPASub-processors

Found something? Responsible disclosure: security@weshield.ai

WeShieldWeShield

The ecosystem for community safety and development — grants, a verified network, risk signals, and case management on one secure platform.

Data residency you control · ca-central-1 today

Product

  • All products
  • Pricing
  • Request access
  • Status

Company

  • About
  • Security
  • AI transparency
  • FAQ
  • Contact

Legal

  • Terms
  • Privacy
  • DPA
  • Subprocessors
© 2026 WeShield AI Inc.
Data residency you control · ca-central-1 today