What you can expect from us, in writing.
Giving a provider administrative access to your systems is a significant decision. This page sets out how North Shield approaches security, privacy, data handling, and service transparency.
This page is maintained by North Shield to answer common security and privacy questions. It describes our own practices and commitments — it is not an independent audit, certification, or third-party attestation.
- Security
- Privacy
- Transparency
Twelve areas, each labelled honestly.
Each topic is tagged so you can tell the difference between a principle we operate by, a control we are building, a service-delivery standard, and a recommendation for your environment.
Security Approach
Layered controls across identity, endpoint, network, data, and recovery, reviewed on a recurring basis.
- Defense in depth rather than a single product
- Documented configuration baselines
- Recurring control review
Privacy Principles
Collect the minimum information needed, use it only for the stated purpose, and keep access controlled.
- Data minimization
- Purpose limitation
- Controlled internal access
Data Handling
Client data encountered during service delivery remains the client's data and is handled accordingly.
- Client ownership of client data
- Secure transfer methods
- Retention reviewed against need
Access Control
Named accounts, least privilege, and review of who holds administrative rights.
- Individual technician accounts
- Least-privilege defaults
- Periodic access review
Remote Access
Remote administration is authorized, attributable, and logged.
- Authorization before access
- MFA on access tooling
- Session logging
Encryption Philosophy
Use encryption in transit and at rest where the platform supports it, and verify it is actually enabled.
- Encryption in transit for administrative access
- Device encryption where supported
- Verification rather than assumption
Incident Readiness
Documented internal escalation and client communication expectations for suspected security events.
- Defined escalation path
- Client notification expectations
- Post-incident review
Vendor Management
Third-party tools and providers are reviewed for security posture, access scope, and exit path.
- Access scope review
- Security posture assessment
- Data portability considerations
Business Continuity
Recovery capability for our own operations and for the environments we support.
- Documented recovery procedures
- Restore validation
- Continuity considerations for critical systems
Responsible Disclosure
A published route for good-faith reporting of suspected security issues on our public website.
- Good-faith reporting encouraged
- Coordinated review before disclosure
- Published policy and rules
Compliance Support
Technical assistance toward control implementation and evidence readiness — not certification.
- Control gap identification
- Documentation and evidence support
- Access and logging improvements
Service Transparency
Clear scope, written recommendations, and honest reporting of unresolved risk.
- Written scope and responsibilities
- Documented recommendations
- Open reporting of outstanding risk
How we treat information.
Applies both to information you give us directly and to data we encounter while delivering service.
Data minimization
Collect only what is needed to deliver or improve the service.
Purpose limitation
Use information for the purpose it was provided, not for unrelated activity.
Controlled access
Internal access limited to the people who need it for the work in front of them.
Secure transfer
Use encrypted channels for credentials, configuration, and sensitive files.
Retention awareness
Keep information only as long as there is a business or legal reason to.
Client ownership
Client data belongs to the client and is returned or removed as agreed.
Vendor review
Assess third parties that would process client information.
Incident escalation
Defined internal escalation for suspected exposure of client information.
Technical help toward controls and evidence.
We support the technical side of compliance work. We do not issue certifications and we are not a substitute for legal, audit, or compliance professionals.
- Understand technical control gaps against a framework or contractual requirement
- Implement security controls such as MFA, logging, patching, and access review
- Prepare technical documentation of configuration and process
- Improve evidence collection for recurring audits or questionnaires
- Review administrative and user access
- Strengthen logging coverage and retention
- Improve backup and recovery readiness
North Shield does not certify legal or regulatory compliance and does not replace qualified legal, audit or compliance professionals.
Security contact and disclosure.
If you believe you have found a security issue affecting this website or our services, we would rather hear about it early.
Good-faith reports are welcome
Use the contact page on this website to reach us. Please include enough information to reproduce the issue and avoid accessing or modifying data that is not yours.
No technology provider can guarantee that an organization will never experience a security incident. North Shield focuses on helping reduce risk, improve resilience, strengthen visibility and prepare organizations to respond appropriately.
The documents behind this page.
Privacy Policy
How North Shield collects, uses, and protects information submitted through this website and provided during service delivery.
Terms of Use
The terms that apply to your use of the North Shield website and the information published on it.
Cookie Policy
What cookies and browser storage this website uses, and what would change if analytics were introduced.
Acceptable Use Policy
Expected conduct for systems, networks, and support services managed or provided by North Shield.
Responsible Disclosure Policy
How to report a suspected security issue affecting this website or our public-facing systems.
Ask us the hard questions early.
Scope, access, responsibilities, and reporting expectations are all better settled before an engagement starts than after.