Skip to content
shuffl

Security at Shuffl

How Shuffl keeps each workspace separate, who can reach its information and where that information goes.

Data isolation and access

  • Separate workspaces

    PostgreSQL row-level security keeps each workspace’s records apart. The API takes the workspace from the credential, not from the request.

  • Roles and HR access

    Owners and administrators manage the workspace. Reading private HR requests is a separate HR responder grant; administrators don’t get it automatically.

  • Directory-backed audiences

    Each knowledge source is published to everyone, administrators only, or chosen departments, teams and roles. One database policy decides who can read it, on the web, in Slack and over MCP.

  • Suspension ends access

    Suspending someone in People ends their access however they sign in, and deactivates their API keys.

Sign-in

  • Single sign-on

    Connect your identity provider over OpenID Connect or SAML for an email domain you verify in DNS. SAML assertions must be signed. People still decides who gets in.

  • Two-factor authentication

    Anyone can turn on an authenticator app, with single-use backup codes. Password, Google and Slack sign-ins then ask for a code. Passkeys need a fingerprint, face or PIN.

  • Protected sign-in

    Tokens from sign-in providers are encrypted in the database. Sign-in, sign-up and password-reset attempts are rate limited, and a password reset signs out every session.

  • Scoped, expiring API keys

    API keys carry only the permissions you pick and expire within 30 days. Shuffl stores a hash of each key, not the key.

Records

  • Audit history

    Administrative actions are recorded with who did what and when. Audit history is kept for the life of the workspace.

  • Export

    Administrators can export the workspace from workspace settings. Each export is itself recorded.

  • Deletion

    A company owner or administrator can delete a workspace, which stops its sending and answering. It is kept for 30 days, during which a company owner or administrator can restore it and a workspace administrator can export it. When the 30 days end, Shuffl erases its workspace records automatically. The company account, company memberships, shared sign-in and directory configuration, and company billing remain.

  • Confidential pulse answers

    Pulse answers are stored apart from who was asked, under a token no application role can reverse, and no role can read them. HR sees totals for 7 or more respondents, frozen when a question closes. Answers are deleted 90 days after close; reports are kept.

AI and your data

  • No training on your content

    Shuffl doesn’t use customer content to train models, or use one customer’s content to improve the service for another.

  • Sent only to answer

    Knowledge retrieved for a question goes to the model provider only to compose the answer to that question, and the answer cites the passages it used.

  • Zero data retention requested

    Model calls ask the AI gateway to use only providers with a zero data retention agreement. Search embeddings are the exception. This request setting does not erase Shuffl’s own conversations, HR records or knowledge; the Privacy Policy describes their retention.

Hosting

  • Application hosting and AI processing

    The application runtime and database are in Northern California, and email delivery is configured in Northern Virginia. The AI gateway’s processing region is not restricted, and Shuffl does not restrict AI inference to a particular region; AI requests may be processed outside the United States.

  • Browser protections

    Every response tells browsers to use HTTPS only and not to show Shuffl inside another site’s frame.

Compliance status

SOC 2 report
Assessment not started
HIPAA
Not assessed
Government cloud or authorization
Not assessed

Report a vulnerability

Email security@shuffl.ai with what you found and how to reproduce it. Please don’t access data that isn’t yours or disrupt the service while testing.