This page explains how BastionShield is built, how we handle your data, what frameworks we align to, and what to do if you find a vulnerability. No marketing copy, just the facts.
These aren't policies that live in a document. They're enforced at build time and verified continuously.
TLS 1.3 enforced. No unencrypted connections accepted. HSTS preloaded.
AES-256 encryption. Keys managed per tenant, rotatable on request.
Zero-trust internal architecture. Engineers access production with short-lived credentials and full audit logging of every action.
Cryptographic chaining on all activity logs. Tamper attempts are detectable and immutable once written.
Annual third-party penetration testing. Critical findings disclosed to affected customers within 24 hours.
24-hour SLA on critical security incidents. Customer notification before public disclosure. Post-incident reports provided.
Automated vulnerability scanning on every build. No known high-severity CVEs in production.
Strict logical data separation per customer. Agent data from one tenant cannot be accessed by another, enforced at the query layer, not just the API layer.
We believe you should know precisely what data BastionShield holds about your AI agents and their activity. No ambiguity. No "we may collect" language.
These mappings are reviewed every quarter and updated when frameworks publish new guidance. We don't claim certifications we don't have.
Security, Availability, Confidentiality
Information security management system
Records of processing activities for AI systems
Patch management, access control, boundary firewalls
Digital operational resilience: AI system oversight
Govern, Map, Measure, Manage AI risk
UK financial services AI explainability and oversight
AI Safety Institute responsible deployment principles
Status definitions: Aligned = evidence directly generated by Bulwark. Mapped = controls addressed with documented evidence approach. Native = built into the platform from day one.
We take security reports seriously. If you find a vulnerability in BastionShield, whether our platform, website, or API, we want to know about it before it becomes a problem for our customers.
We commit to acknowledging your report within 24 hours, providing a resolution timeline within 72 hours, and crediting you in our disclosure if you want that recognition. We won't pursue legal action against researchers who follow these guidelines.
Please don't access, modify, or exfiltrate customer data during testing. Report to us before publishing. Give us a reasonable window to patch before public disclosure.
Report a vulnerabilityIf you're running a vendor security review, we have documentation packages available on request. We respond to security questionnaires directly, no generic PDFs.