Security at Shuffl
How Shuffl keeps each workspace separate, who can reach its information and where that information goes.
Data isolation and access
Separate workspaces
PostgreSQL row-level security keeps each workspace’s records apart. The API takes the workspace from the credential, not from the request.
Roles and HR access
Owners and administrators manage the workspace. Reading private HR requests is a separate HR responder grant; administrators don’t get it automatically.
Directory-backed audiences
Each knowledge source is published to everyone, administrators only, or chosen departments, teams and roles. One database policy decides who can read it, on the web, in Slack and over MCP.
Suspension ends access
Suspending someone in People ends their access however they sign in, and deactivates their API keys.
Sign-in
Single sign-on
Connect your identity provider over OpenID Connect or SAML for an email domain you verify in DNS. SAML assertions must be signed. People still decides who gets in.
Two-factor authentication
Anyone can turn on an authenticator app, with single-use backup codes. Password, Google and Slack sign-ins then ask for a code. Passkeys need a fingerprint, face or PIN.
Protected sign-in
Tokens from sign-in providers are encrypted in the database. Sign-in, sign-up and password-reset attempts are rate limited, and a password reset signs out every session.
Scoped, expiring API keys
API keys carry only the permissions you pick and expire within 30 days. Shuffl stores a hash of each key, not the key.
Records
Audit history
Administrative actions are recorded with who did what and when. Audit history is kept for the life of the workspace.
Export
Administrators can export the workspace from workspace settings. Each export is itself recorded.
Deletion
A company owner or administrator can delete a workspace, which stops its sending and answering. It is kept for 30 days, during which a company owner or administrator can restore it and a workspace administrator can export it. When the 30 days end, Shuffl erases its workspace records automatically. The company account, company memberships, shared sign-in and directory configuration, and company billing remain.
Confidential pulse answers
Pulse answers are stored apart from who was asked, under a token no application role can reverse, and no role can read them. HR sees totals for 7 or more respondents, frozen when a question closes. Answers are deleted 90 days after close; reports are kept.
AI and your data
No training on your content
Shuffl doesn’t use customer content to train models, or use one customer’s content to improve the service for another.
Sent only to answer
Knowledge retrieved for a question goes to the model provider only to compose the answer to that question, and the answer cites the passages it used.
Zero data retention requested
Model calls ask the AI gateway to use only providers with a zero data retention agreement. Search embeddings are the exception. This request setting does not erase Shuffl’s own conversations, HR records or knowledge; the Privacy Policy describes their retention.
Hosting
Application hosting and AI processing
The application runtime and database are in Northern California, and email delivery is configured in Northern Virginia. The AI gateway’s processing region is not restricted, and Shuffl does not restrict AI inference to a particular region; AI requests may be processed outside the United States.
Browser protections
Every response tells browsers to use HTTPS only and not to show Shuffl inside another site’s frame.
Compliance status
- SOC 2 report
- Assessment not started
- HIPAA
- Not assessed
- Government cloud or authorization
- Not assessed
Report a vulnerability
Email security@shuffl.ai with what you found and how to reproduce it. Please don’t access data that isn’t yours or disrupt the service while testing.