Security & Compliance
Shrike is the independent trust layer for AI agent governance — mapping directly to the NIST Cybersecurity Framework Profile for Generative AI.
Executive Summary
The NIST Internal Report 8596 categorizes AI security into three focus areas: Secure, Thwart, and Defend.
Shrike acts as the infrastructure layer for the "Secure" and "Thwart" directives, providing the "monitoring of inputs and outputs" explicitly required by Subcategory DE.CM-01.
This document demonstrates how Shrike's capabilities map directly to NIST requirements, supporting organizations' compliance efforts while deploying AI systems with confidence.
Focus Area Alignment
"SECURE" Focus Area
Goal: Secure AI systems from adversarial inputs.
- Input ShieldPrompt injection detection & blocking
- Output FilterPII/SCI redaction in real-time
- Data-in-Transit ProtectionTLS 1.3 in transit; retention configurable — see Privacy Policy
"THWART" Focus Area
Goal: Resilience against autonomous attacks.
- ThreatSense EngineBehavioral analysis & pattern learning
- Red Team Simulator6,500+ adversarial variants (647 base × 5 mutations)
- Self-Healing DefenseAutomatic rule adaptation from new threats
NIST CSF 2.0 Control Map
| Control ID | NIST Requirement | Shrike Capability |
|---|---|---|
| DE.CM-01 | "Inputs and outputs may be monitored to detect adverse events." | ThreatSense Engine: real-time inspection of every prompt, response, tool call, and A2A message. p50 <15ms on pattern layers; the deeper LLM semantic layer adds ~300–450ms only on ambiguous content. |
| PR.DS-10 | "Confidentiality of data-in-use is protected." | PII Redaction Engine: Masks SSNs, API keys, and sensitive data in real-time. |
| GV.SC-01 | "Input data verified to detect poisoning." | Forensic Audit Trail: Immutable payload hashing for chain of custody. |
| ID.RA-01 | "Vulnerabilities are identified and documented." | Red Team Simulator: Automated testing against OWASP LLM Top 10. |
| PR.IR-01 | "Networks, systems, and resources are monitored for security events." | Real-time Dashboard: Continuous monitoring with alerting and incident response. |
| RS.AN-01 | "Records of response actions are maintained." | Incident Management: Full audit trail with remediation tracking. |
Implementation Architecture
"Shrike runs as an inline policy gateway at the trust boundary — every prompt, response, tool call, and agent message is evaluated server-side before execution. Integration via MCP config or one-line SDK init."
Minimal Integration
MCP config or one-line SDK init
Air-Gapped Deployment
Signed policy bundles, zero outbound — available under Enterprise engagement on GKE Confidential Nodes
Cloud-Agnostic
GCP (live) · AWS (planned) · On-Prem (Enterprise)
Additional Framework Alignment
Year-1 target; audit vendor selection in progress
Roadmap; 3PAO not yet engaged
Meeting GPAI + Art. 50 transparency obligations; EU enforcement powers live Aug 2, 2026. Standalone high-risk (Annex III) follows Dec 2, 2027 (Digital Omnibus, in force 27 Jul 2026)
10/10 categories mapped — view mapping
Compliance Reporting
Enterprise customers generate compliance posture reports that map detected policy violations to control requirements across five frameworks — with per-control scoring and CSV export for auditors and GRC workflows.
Subprocessors
Required disclosure under GDPR Art. 28. Shrike uses the following subprocessors to deliver the service. Customer scan content is processed in transit only — see Privacy Policy for retention details.
| Subprocessor | Purpose | Region | Data Class |
|---|---|---|---|
| Google Cloud Platform | Compute (Cloud Run) + database (Cloud SQL) | us-central1 (default); EU on request | All scan traffic + customer metadata |
| Google Vertex AI | L7 cognitive (LLM) analysis | us-central1 | Ambiguous prompt content (~5% of traffic) |
| Stripe | Subscription billing for Pro and Team tiers | US | Billing email + payment metadata (no scan content) |
| Google Workspace (Gmail SMTP) | Transactional email (signup, alerts) | US | Customer email address |
| GCP Marketplace / Cloud Commerce | Enterprise marketplace billing | US | Procurement account ID |
Enterprise customers receive 30-day advance notice of subprocessor additions or changes via the contractual notification process.
Security Posture & Disclosure
Incident History
No reportable security incidents to date.
Customer notification SLA: 24 hours from confirmation, per Pro/Team/Enterprise contract terms.
Vulnerability Disclosure
Report vulnerabilities to security@shrikesecurity.com.
Acknowledgment within 2 business days. Coordinated disclosure with credit. Formal bug bounty program on the roadmap; interim rewards handled case-by-case.
Common Questions
Does deploying Shrike make my AI app SOC 2 compliant?
No tool makes you SOC 2 compliant — your auditor issues that opinion about your organization. What an auditor accepts is evidence that your controls operated. Shrike produces exactly that for the AI part of your stack: a per-action audit trail where every agent action is evaluated against your policy and every allow, warn, require-approval, and block is recorded and exportable. When a security questionnaire asks how you control what your AI can do, you answer with records instead of intentions. It shortens your path; it does not replace your audit.
How does Shrike help with the EU AI Act?
Shrike maps to the high-risk risk-management (Article 9) and transparency (Article 50) control expectations: pre-execution evaluation of agent actions, human-in-the-loop approval on consequential actions, and a retained per-action decision trail. Article 50 transparency obligations and GPAI enforcement powers are live as of August 2, 2026; standalone high-risk obligations follow on December 2, 2027. This is posture alignment and evidence, not certification.
What evidence can I hand my auditor or a customer security review?
A per-action record: what the agent attempted, the verdict (allow, warn, require-approval, or block), the policy that applied, who approved an override if one occurred, and a timestamp — retained and exportable, plus compliance reports mapped to HIPAA, GDPR, SOC 2, ISO 27001, and PCI DSS. Evidence packages and DPAs are available on request.
Ready to achieve AI compliance?
Schedule a security assessment with our team to see how Shrike maps to your specific compliance requirements.
Last reviewed: 2026-07-11 · Evidence packages and DPAs: · Vulnerability disclosure: security@shrikesecurity.com
Shrike Security, Inc. · UEI YU85T9ZQ5ZB8 · Dallas, TX