Security and privacy
Security and Data Protection
Security and privacy are core considerations in how Shinobi AI designs, builds, and operates its products.
Last updated 6 October 2026
Our approach
We aim to minimize unnecessary data collection, restrict access to customer information, and use infrastructure and technology providers with appropriate security controls.
Data minimization
Shinobi AI designs its systems to collect and retain only the information required to provide the relevant service.
Data handling and retention requirements may vary depending on the product, integration, and customer agreement.
AI data handling
Where Shinobi AI uses the OpenAI API, data submitted through the API is not used to train OpenAI models unless data sharing is explicitly enabled.
Our OpenAI organization supports Zero Data Retention (ZDR) for eligible workloads. Whether ZDR applies to a given workload depends on the API endpoints it uses and how its project is configured.
When a supported workload is configured to use ZDR, eligible customer content is not retained by OpenAI in abuse-monitoring logs or as application state where the applicable API endpoint supports Zero Data Retention.
Not all OpenAI API features and endpoints are eligible for ZDR. Workloads that require persistent application state, file storage, or other non-ZDR-compatible functionality may be handled under different retention controls.
Reference: OpenAI API Data Controls
Encryption in transit
Connections to Shinobi AI web services are protected using HTTPS/TLS encryption.
Access control
Access to production systems and customer information is restricted to authorized personnel and service accounts based on operational requirements.
Infrastructure and service providers
Shinobi AI uses third-party infrastructure and technology providers to operate parts of its services.
We evaluate how customer information is handled by the providers used in our systems and aim to minimize unnecessary exposure of customer data.
Data retention and deletion
Retention requirements may vary by product and customer agreement.
Where applicable, customer data may be deleted according to agreed retention requirements, product configuration, and contractual obligations.
Security incident response
Shinobi AI maintains processes for identifying, investigating, and responding to suspected security incidents.
Customer-specific requirements
Security, retention, integration, and data-processing requirements may differ between products and enterprise customer deployments.
Customers with specific security or compliance requirements can contact Shinobi AI for additional information regarding architecture, data flows, and applicable controls.
Security questions?
For security, privacy, or data-protection questions, contact our team.
