Security, Privacy &
Compliance Standards
How we protect client systems, source code, and confidential data. From penetration testing and cloud infrastructure to sovereign AI deployments, explore our commitments under global and Indian standards.
European data sovereignty & SCCs
Security, availability & confidentiality
BAA terms & healthcare data safeguards
Indian digital personal data protection
EU GDPR
When partnering with European clients or handling systems processing personal data of EU and EEA residents, SHELL INFOSEC strictly operates as a compliant Data Processor under Article 28 of the GDPR. We incorporate standard contractual clauses, execute Data Protection Impact Assessments (DPIAs), and build all architectures following Privacy by Design and by Default principles.
We execute formal, binding DPAs with every enterprise client handling personal data, incorporating the European Commission Standard Contractual Clauses (Decision 2021/914) Module 2 and Module 3.
All international data pathways are secured with client-held encryption keys and localized processing environments, preventing unauthorized third-country government surveillance in compliance with Schrems II.
Prior to deploying autonomous AI agents, machine learning pipelines, or complex cloud architectures, our security team conducts formal DPIAs to identify and mitigate privacy risks.
We provide structured technical protocols for verifying identities and fulfilling requests for access, rectification, erasure ('Right to be Forgotten'), restriction, and data portability without delay.
Technical & Operational Safeguards
The technical defenses, encryption baselines, and human workflows that ensure zero compromise across every client engagement.
End-to-End Transport Security
All web traffic, API integrations, and internal communications strictly require TLS 1.3 with perfect forward secrecy. Legacy protocols (TLS 1.0, 1.1) are disabled across all edge endpoints.
Hardware-Backed Encryption
All client data, reports, and engagement artifacts are encrypted at rest using AES-256-GCM. Decryption keys are managed via hardware security modules (HSMs) with strict separation of duties.
Hardware Multi-Factor Authentication
Every engineer and researcher at SHELL INFOSEC is required to authenticate using physical, phishing-resistant FIDO2 hardware security keys. SMS and traditional OTPs are prohibited for production access.
Edge Defense & Rate Limiting
Enterprise edge protection inspects inbound requests against real-time threat intelligence feeds, mitigating distributed denial-of-service attempts and blocking automated vulnerability scanners.
Rapid Breach Escalation Protocol
In the event of any suspected security anomaly or credential compromise, our on-call incident response team mobilizes immediately with forensic logging, memory isolation, and client notification.
Defensive Code & Dependency Audits
Our repositories undergo continuous static analysis (SAST), software composition analysis (SCA) for third-party vulnerabilities, and recurring third-party security audits.
Request Audit Summaries & Compliance Packages
Under mutual non-disclosure agreement, enterprise procurement and compliance officers can request our comprehensive assurance packages, including: