Skip to content
Trust center

What you can expect from us, in writing.

Giving a provider administrative access to your systems is a significant decision. This page sets out how North Shield approaches security, privacy, data handling, and service transparency.

This page is maintained by North Shield to answer common security and privacy questions. It describes our own practices and commitments — it is not an independent audit, certification, or third-party attestation.

  • Security
  • Privacy
  • Transparency
Topics

Twelve areas, each labelled honestly.

Each topic is tagged so you can tell the difference between a principle we operate by, a control we are building, a service-delivery standard, and a recommendation for your environment.

Operating principle

Security Approach

Layered controls across identity, endpoint, network, data, and recovery, reviewed on a recurring basis.

  • Defense in depth rather than a single product
  • Documented configuration baselines
  • Recurring control review
Operating principle

Privacy Principles

Collect the minimum information needed, use it only for the stated purpose, and keep access controlled.

  • Data minimization
  • Purpose limitation
  • Controlled internal access
Service-delivery standard

Data Handling

Client data encountered during service delivery remains the client's data and is handled accordingly.

  • Client ownership of client data
  • Secure transfer methods
  • Retention reviewed against need
Service-delivery standard

Access Control

Named accounts, least privilege, and review of who holds administrative rights.

  • Individual technician accounts
  • Least-privilege defaults
  • Periodic access review
Service-delivery standard

Remote Access

Remote administration is authorized, attributable, and logged.

  • Authorization before access
  • MFA on access tooling
  • Session logging
Operating principle

Encryption Philosophy

Use encryption in transit and at rest where the platform supports it, and verify it is actually enabled.

  • Encryption in transit for administrative access
  • Device encryption where supported
  • Verification rather than assumption
Planned operational control

Incident Readiness

Documented internal escalation and client communication expectations for suspected security events.

  • Defined escalation path
  • Client notification expectations
  • Post-incident review
Planned operational control

Vendor Management

Third-party tools and providers are reviewed for security posture, access scope, and exit path.

  • Access scope review
  • Security posture assessment
  • Data portability considerations
Planned operational control

Business Continuity

Recovery capability for our own operations and for the environments we support.

  • Documented recovery procedures
  • Restore validation
  • Continuity considerations for critical systems
Operating principle

Responsible Disclosure

A published route for good-faith reporting of suspected security issues on our public website.

  • Good-faith reporting encouraged
  • Coordinated review before disclosure
  • Published policy and rules
Client-environment recommendation

Compliance Support

Technical assistance toward control implementation and evidence readiness — not certification.

  • Control gap identification
  • Documentation and evidence support
  • Access and logging improvements
Service-delivery standard

Service Transparency

Clear scope, written recommendations, and honest reporting of unresolved risk.

  • Written scope and responsibilities
  • Documented recommendations
  • Open reporting of outstanding risk
Data handling

How we treat information.

Applies both to information you give us directly and to data we encounter while delivering service.

Data minimization

Collect only what is needed to deliver or improve the service.

Purpose limitation

Use information for the purpose it was provided, not for unrelated activity.

Controlled access

Internal access limited to the people who need it for the work in front of them.

Secure transfer

Use encrypted channels for credentials, configuration, and sensitive files.

Retention awareness

Keep information only as long as there is a business or legal reason to.

Client ownership

Client data belongs to the client and is returned or removed as agreed.

Vendor review

Assess third parties that would process client information.

Incident escalation

Defined internal escalation for suspected exposure of client information.

Compliance support

Technical help toward controls and evidence.

We support the technical side of compliance work. We do not issue certifications and we are not a substitute for legal, audit, or compliance professionals.

  • Understand technical control gaps against a framework or contractual requirement
  • Implement security controls such as MFA, logging, patching, and access review
  • Prepare technical documentation of configuration and process
  • Improve evidence collection for recurring audits or questionnaires
  • Review administrative and user access
  • Strengthen logging coverage and retention
  • Improve backup and recovery readiness
Scope of compliance support

North Shield does not certify legal or regulatory compliance and does not replace qualified legal, audit or compliance professionals.

Reporting a concern

Security contact and disclosure.

If you believe you have found a security issue affecting this website or our services, we would rather hear about it early.

Good-faith reports are welcome

Use the contact page on this website to reach us. Please include enough information to reproduce the issue and avoid accessing or modifying data that is not yours.

No absolute guarantees

No technology provider can guarantee that an organization will never experience a security incident. North Shield focuses on helping reduce risk, improve resilience, strengthen visibility and prepare organizations to respond appropriately.

Next step

Ask us the hard questions early.

Scope, access, responsibilities, and reporting expectations are all better settled before an engagement starts than after.