Security

Last updated: July 18, 2026

1. Data in Transit

All traffic between your browser and SHIJO.AI is encrypted using TLS/SSL. We do not serve the application or accept form submissions over unencrypted HTTP.

2. Password & Session Security

Passwords are hashed with bcrypt before storage — we never store or have access to your plaintext password. Sessions are managed with an HTTP-only, secure cookie, which means the session token is not readable by page scripts, reducing exposure to cross-site scripting attacks.

3. Payment Security

All payment processing is handled by Stripe, a PCI-DSS Level 1 certified payment processor. Your card details are sent directly to Stripe and never touch our servers — we only store a Stripe customer and subscription reference.

4. Access Controls

Administrative access to account and billing data is restricted to authorized SHIRO Technologies personnel. Admin privileges are re-verified against our database on every request rather than trusted from a client-supplied token, so a compromised or forged token alone cannot grant administrative access.

5. Infrastructure

SHIJO.AI is hosted on Vercel and backed by Neon (managed PostgreSQL). Our AI features are powered by Anthropic's Claude models. Each of these providers maintains its own security program; see our GDPR Compliance page for the full list of sub-processors we use.

6. Your Own Data Controls

You can export a complete copy of your account data, or permanently delete your account and all associated data, at any time from Dashboard → Settings → Data & Privacy. Account deletion requires re-entering your password as a safeguard against a stolen or shared session.

7. Incident Notification

If we become aware of a security incident that compromises the confidentiality, integrity, or availability of your personal information in a manner that requires notification under applicable law, we will notify affected users and any relevant authorities without unreasonable delay, consistent with Section 8 of our Privacy Policy.

8. No Guarantee

We use commercially reasonable, industry-standard measures to protect your data, but no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.

9. Reporting a Security Issue

If you believe you've found a security vulnerability in SHIJO.AI, please report it to legal@shijo.ai with as much detail as possible. Please do not publicly disclose a suspected vulnerability until we've had a reasonable opportunity to investigate and address it.