SHELL INFOSEC

Security, Privacy &
Compliance Standards

How we protect client systems, source code, and confidential data. From penetration testing and cloud infrastructure to sovereign AI deployments, explore our commitments under global and Indian standards.

GDPREU SOVEREIGN
EU GDPR

European data sovereignty & SCCs

SOC 2TYPE IIAICPA
SOC 2 Type II

Security, availability & confidentiality

HIPAA
HIPAA Ready

BAA terms & healthcare data safeguards

DPDP ACTINDIA · 2023
DPDP Act 2023

Indian digital personal data protection

Headquarters: New Delhi, India
MSME Reg: UDYAM-DL-09-0012062
Attestation Period: 2026 Active Cycle
GDPREU SOVEREIGN
European Data Protection Board · Regulation (EU) 2016/679

EU GDPR

Active Operating Standard

When partnering with European clients or handling systems processing personal data of EU and EEA residents, SHELL INFOSEC strictly operates as a compliant Data Processor under Article 28 of the GDPR. We incorporate standard contractual clauses, execute Data Protection Impact Assessments (DPIAs), and build all architectures following Privacy by Design and by Default principles.

Article 28 Data Processing Agreement (DPA)

We execute formal, binding DPAs with every enterprise client handling personal data, incorporating the European Commission Standard Contractual Clauses (Decision 2021/914) Module 2 and Module 3.

International Data Transfer Safeguards

All international data pathways are secured with client-held encryption keys and localized processing environments, preventing unauthorized third-country government surveillance in compliance with Schrems II.

Data Protection Impact Assessments (DPIAs)

Prior to deploying autonomous AI agents, machine learning pipelines, or complex cloud architectures, our security team conducts formal DPIAs to identify and mitigate privacy risks.

Full Exercise of Data Subject Rights (Articles 15–22)

We provide structured technical protocols for verifying identities and fulfilling requests for access, rectification, erasure ('Right to be Forgotten'), restriction, and data portability without delay.

Our Operational Standard: Zero commercial sale or monetisation of personal data, no behavioral cross-site tracking, and European Union data residency options for all sovereign cloud deployments.
Engineering Safeguards

Technical & Operational Safeguards

The technical defenses, encryption baselines, and human workflows that ensure zero compromise across every client engagement.

Production Standards Verified
Data in TransitTLS 1.3 with HSTS Preload

End-to-End Transport Security

All web traffic, API integrations, and internal communications strictly require TLS 1.3 with perfect forward secrecy. Legacy protocols (TLS 1.0, 1.1) are disabled across all edge endpoints.

Standard Operational Procedure
Data at RestAES-256-GCM Envelope Encryption

Hardware-Backed Encryption

All client data, reports, and engagement artifacts are encrypted at rest using AES-256-GCM. Decryption keys are managed via hardware security modules (HSMs) with strict separation of duties.

Standard Operational Procedure
AuthenticationFIDO2 / WebAuthn Physical Keys

Hardware Multi-Factor Authentication

Every engineer and researcher at SHELL INFOSEC is required to authenticate using physical, phishing-resistant FIDO2 hardware security keys. SMS and traditional OTPs are prohibited for production access.

Standard Operational Procedure
Perimeter & NetworkDDoS Mitigation & Layer 7 WAF

Edge Defense & Rate Limiting

Enterprise edge protection inspects inbound requests against real-time threat intelligence feeds, mitigating distributed denial-of-service attempts and blocking automated vulnerability scanners.

Standard Operational Procedure
Incident Response1-Hour Critical Incident SLA

Rapid Breach Escalation Protocol

In the event of any suspected security anomaly or credential compromise, our on-call incident response team mobilizes immediately with forensic logging, memory isolation, and client notification.

Standard Operational Procedure
Continuous TestingAutomated SAST & Regular Pen Testing

Defensive Code & Dependency Audits

Our repositories undergo continuous static analysis (SAST), software composition analysis (SCA) for third-party vulnerabilities, and recurring third-party security audits.

Standard Operational Procedure
Audit Documentation & Due Diligence

Request Audit Summaries & Compliance Packages

Under mutual non-disclosure agreement, enterprise procurement and compliance officers can request our comprehensive assurance packages, including:

Standard HIPAA BAA Package
SOC 2 Type II Executive Summary
GDPR Article 28 DPA with EU SCCs
Indian DPDP Data Fiduciary Schedule