# Security and trust at Shiken

> Shiken is SOC 2 Type II and ISO 27001 certified and GDPR compliant, and does not train AI models on customer data by default.

Canonical page: https://shiken.ai/security

## Certifications and compliance

- SOC 2 Type II
- ISO 27001
- GDPR compliant, with a Data Processing Agreement available
- Enterprise plans add org-wide model-training opt-out, DPA, SLA and a dedicated CSM

## Enterprise controls

- SSO/SAML and SCIM provisioning
- Role-based access control inside an organisation
- Data residency and retention options discussed per contract

## Documents

- [Privacy Policy](https://shiken.ai/privacy)
- [Terms](https://shiken.ai/terms)
- [Data Processing Agreement](https://shiken.ai/data-processing-agreement)

## Related

- [Shiken for enterprise](https://shiken.ai/enterprise)
- [Contact Shiken sales](https://shiken.ai/contact-sales)

## Machine-readable index

- [llms.txt](https://shiken.ai/llms.txt) — site index for AI assistants
- [llms-full.txt](https://shiken.ai/llms-full.txt) — full product reference
- [pricing.md](https://shiken.ai/pricing.md) — every plan and price
- [openapi.json](https://shiken.ai/openapi.json) — the organisation API
