Trust & sovereignty

Security you can audit.

We ask you to trust us with the most sensitive picture of your organisation. Here is exactly how we earn and protect that trust.

Our own security posture

We hold ourselves to the standard we sell. WoneShield is dogfooded on our own infrastructure — continuously assessed, attacked and validated by the same engine our customers run.

Data sovereignty & residency

Your data stays yours. WoneShield can run entirely within your own environment, in your jurisdiction, with clear retention and deletion terms agreed in writing. No data leaves your premises unless you choose the hosted option.

Compliance frameworks

We map to and support SOC 2, ISO 27001 / 22301, HIPAA, PCI DSS, NIST and CIS — with evidence collection and gap-mapping built in via WoneShield Comply.

Authorisation & scope

Every assessment and simulation runs only under written authorisation and an agreed scope. Production systems are protected — anything that could affect availability runs against an isolated reconstruction. You hold a stop switch that halts everything immediately.

Encryption & handling

Credentials and secrets are encrypted at rest and in transit. We report honestly — where we can't verify something, we say so rather than assert a false pass.

Responsible disclosure

Found something? We want to hear from you. Reach our security team via the contact page and we'll respond promptly.