Trust Center

Trust, verified.

Certifications, policies, subprocessors, and security controls — everything your procurement and security teams need in one place.

Certifications & standards

GDPR

Compliant

Data processing compliant with EU General Data Protection Regulation. Standard DPA included on all plans.

EU Infrastructure

Active

Managed platform runs on EU-owned infrastructure (Scaleway, France). Enterprise self-hosting on Azure, AWS, or GCP available.

ISO 27001

In progress

Information security management system certification. Currently in the implementation phase.

Policies & documents

Data Processing Agreement

Standard DPA included on all plans. Custom DPA available for Enterprise.

View DPA

Privacy Policy

How we collect, use, and protect your data.

Read policy

Terms of Service

Terms governing use of the Shaep platform.

Read terms

Subprocessors

All subprocessors are EU-based. We notify customers in advance of any changes.

ProviderLocationPurpose
ScalewayFranceCloud infrastructure (compute, storage, networking)
ForgejoSelf-hosted, EUSource code hosting and CI/CD
HetznerGermanyDNS and edge infrastructure

Security controls

Encryption at rest and in transit
Container isolation per application
Network policy enforcement
Automated vulnerability scanning
Secrets management (encrypted, scoped)
Role-based access control
SSO / SAML / OIDC support
Audit trails on every release
Dev / prod environment separation
Automated infrastructure patching

Frequently asked questions

How does the DPA work? +

A standard Data Processing Agreement is included on all plans. Enterprise customers can request a custom DPA tailored to their organisation.

Where are you with ISO 27001? +

We are currently in the implementation phase — policies, risk assessments, and controls are being formalised. Contact us for a status update.

How do you handle data deletion requests? +

Data deletion requests are processed within 30 days as required by GDPR. All application data, backups, and logs are purged. We provide confirmation of deletion on request.

Do you notify customers of subprocessor changes? +

Yes. We maintain a subprocessor list and notify customers in advance of any changes, giving them time to review and object if needed.

Can we run a vendor security assessment? +

Yes. We're happy to answer security questionnaires. Contact us to schedule.

Need documentation for procurement?

We'll provide a DPA, security questionnaire responses, or schedule a walkthrough with your security team.

Get in touch