Skip to main content

Security First

Shipwright AI is designed from the ground up with security best practices woven into every layer — from infrastructure to application code to operational procedures.

HTTPS Everywhere

All communications are encrypted with TLS 1.3. We enforce HTTPS across every endpoint, API, and webhook. HSTS headers prevent downgrade attacks.

Encryption at Rest

Sensitive data stored in our databases and object storage is encrypted using AES-256. Encryption keys are managed through dedicated key management services.

Authentication

We use OAuth 2.0 / OpenID Connect for user authentication. Multi-factor authentication support is on our security roadmap. Session tokens are short-lived and securely stored.

Authorization & Least Privilege

Role-based access control (RBAC) restricts system actions to authorized users. Internal services operate under the Principle of Least Privilege — each component has only the permissions it needs.

Secrets Management

API keys, tokens, and credentials are never stored in source code. We use environment-based secrets management with encrypted storage and controlled access.

Secure Development Practices

Our CI/CD pipelines include automated dependency scanning, static analysis (SAST), and secrets detection. Dependencies are reviewed and updated regularly.

Dependency Scanning

Automated vulnerability scanning runs against every dependency in our supply chain. Known CVEs are triaged and patched on a risk-prioritized schedule.

Logging & Monitoring

Comprehensive audit logs track access, modifications, and administrative actions. Active monitoring detects anomalies, unauthorized access attempts, and unusual patterns.

Backup Strategy

Database backups are performed on a scheduled basis with encrypted storage. Backup restoration procedures are tested periodically to ensure data recoverability.

Incident Response

We maintain a documented incident response plan covering identification, containment, eradication, recovery, and post-mortem. Security incidents are communicated transparently.

Vulnerability Management

We follow a structured vulnerability management process: report, triage, prioritize, remediate, and verify. Critical vulnerabilities are addressed within 48 hours.

Account Security

Account lockout policies protect against brute force attacks. Session management includes automatic timeout and concurrent session limits. Password requirements follow NIST guidelines.

Data Retention & Privacy

Data Retention

  • User data is retained only as long as the account is active
  • Deleted accounts are purged within 30 days
  • Logs are retained for security and compliance purposes
  • Users can request full data export or deletion

AI & Code Data

  • Your code is never used to train AI models without explicit opt-in
  • AI conversations are processed transiently for response generation
  • You retain full ownership of all code and content
  • Third-party AI providers are bound by data processing agreements

Security Roadmap

While we apply rigorous security controls today, we are actively working toward formal compliance programs as the company scales. We do not claim certifications we have not earned.

SOC 2 Type II

Roadmap

Planned as the company scales to enterprise customers.

ISO 27001

Roadmap

Information security management system certification.

Penetration Testing

Planned

Third-party penetration testing before GA launch.

Responsible Disclosure

We take vulnerability reports seriously. If you discover a security issue, please report it responsibly. We commit to acknowledging reports within 48 hours.