We govern AI agents.
We hold ourselves to the same standard.

This page explains how BastionShield is built, how we handle your data, what frameworks we align to, and what to do if you find a vulnerability. No marketing copy, just the facts.

Platform security controls.

These aren't policies that live in a document. They're enforced at build time and verified continuously.

01

Data in transit

TLS 1.3 enforced. No unencrypted connections accepted. HSTS preloaded.

02

Data at rest

AES-256 encryption. Keys managed per tenant, rotatable on request.

03

Access controls

Zero-trust internal architecture. Engineers access production with short-lived credentials and full audit logging of every action.

04

Log integrity

Cryptographic chaining on all activity logs. Tamper attempts are detectable and immutable once written.

05

Penetration testing

Annual third-party penetration testing. Critical findings disclosed to affected customers within 24 hours.

06

Incident response

24-hour SLA on critical security incidents. Customer notification before public disclosure. Post-incident reports provided.

07

Dependency management

Automated vulnerability scanning on every build. No known high-severity CVEs in production.

08

Tenant isolation

Strict logical data separation per customer. Agent data from one tenant cannot be accessed by another, enforced at the query layer, not just the API layer.

Exactly what we store. And exactly what we do not.

We believe you should know precisely what data BastionShield holds about your AI agents and their activity. No ambiguity. No "we may collect" language.

What we store

  • Agent registration metadata (name, owner, purpose, timestamps)
  • Activity logs (prompts, outputs, tool calls, data access events)
  • Permission policy definitions per agent
  • Risk detection flags and anomaly alerts
  • Compliance evidence packages when exported

What we do not store

  • Raw customer data accessed by agents. We log the access event, not the data itself
  • Payment card information of any kind
  • Personal biometric data
  • Your end users' personal data beyond what you include in agent prompts, and we recommend you don't

Eight frameworks. Mapped and maintained.

These mappings are reviewed every quarter and updated when frameworks publish new guidance. We don't claim certifications we don't have.

SOC 2 Type II

Aligned

Security, Availability, Confidentiality

ISO 27001:2022

Aligned

Information security management system

GDPR Article 30

Native

Records of processing activities for AI systems

UK Cyber Essentials+

Aligned

Patch management, access control, boundary firewalls

DORA (EU)

Mapped

Digital operational resilience: AI system oversight

NIST AI RMF

Mapped

Govern, Map, Measure, Manage AI risk

FCA AI Guidance

Mapped

UK financial services AI explainability and oversight

UK DSIT AI Safety

Aligned

AI Safety Institute responsible deployment principles

Status definitions: Aligned = evidence directly generated by Bulwark. Mapped = controls addressed with documented evidence approach. Native = built into the platform from day one.

Found a vulnerability?
Tell us. Please.

We take security reports seriously. If you find a vulnerability in BastionShield, whether our platform, website, or API, we want to know about it before it becomes a problem for our customers.

We commit to acknowledging your report within 24 hours, providing a resolution timeline within 72 hours, and crediting you in our disclosure if you want that recognition. We won't pursue legal action against researchers who follow these guidelines.

Please don't access, modify, or exfiltrate customer data during testing. Report to us before publishing. Give us a reasonable window to patch before public disclosure.

Report a vulnerability

What to include in your report

  • Type of vulnerability (XSS, injection, auth bypass, etc.)
  • Steps to reproduce: specific and reproducible
  • Potential impact and affected systems
  • Your contact details for follow-up
  • Whether you want public credit

Our timeline commitments

Acknowledgement24 hours
Initial assessment72 hours
Fix timeline provided5 business days
Critical patches deployedTarget 48 hours

Questions about our security posture?

If you're running a vendor security review, we have documentation packages available on request. We respond to security questionnaires directly, no generic PDFs.