Security & Compliance Overview
This document provides a corporate security and regulatory compliance overview of Taleshape OÜ, the company behind Shaper. It is designed specifically for enterprise Information Security (InfoSec), compliance, and procurement teams evaluating Taleshape as a software and enterprise support vendor.
For deep technical details regarding Shaper’s software application architecture, cryptographic signing, DuckDB sandboxing, and CI/CD supply chain hardening, consult our accompanying Shaper Security Whitepaper.
1. Company Profile & Operating Model
Section titled “1. Company Profile & Operating Model”Taleshape OÜ is a registered European private limited company founded in Estonia.
| Company Attribute | Details |
|---|---|
| Legal Entity Name | Taleshape OÜ |
| Commercial Registry Code | 16962132 |
| Registered Address | Sepapaja tn 6, 15551 Tallinn, Estonia |
| Country of Incorporation | Estonia (European Union) |
| Primary Contact | contact@taleshape.com |
| Security & Compliance Inquiries | security@taleshape.com |
Core Business Model: Enterprise Infrastructure Support
Section titled “Core Business Model: Enterprise Infrastructure Support”Taleshape’s core commercial focus is providing Enterprise Support and Managed Deployment Services for Shaper deployed directly inside customer-managed infrastructure (private VPCs, bare-metal servers, or container infrastructure).
We currently do not operate a multi-tenant cloud SaaS where customer analytical data or records are hosted on our infrastructure. Instead:
- The software runs in your perimeter: Shaper executes entirely on servers and networks owned and managed by the customer.
- Customer maintains complete data sovereignty: Your databases, analytical queries, and dashboards remain within your VPC or data center at all times.
- Taleshape maintains zero direct access: We deliver proactive version upgrades, configuration hardening, feature enhancements, and bug fixes exclusively through code Pull Requests (GitOps) to customer-controlled repositories.
2. Zero-Access & On-Premise Support Architecture
Section titled “2. Zero-Access & On-Premise Support Architecture”The most effective method of eliminating vendor security and compliance risk is an architecture of non-access:
graph LR
subgraph CustomerInfra["Customer Managed Perimeter (VPC / On-Premise)"]
subgraph DataPerimeter["Customer Data Tier (Protected Information / Sensitive Data)"]
ClinicalDB["Production Databases / Analytical Warehouses / S3"]
end
subgraph ShaperDeployment["Shaper Deployment (Local Execution)"]
ShaperApp["Shaper Analytics Service<br/>• Self-contained Docker container<br/>• Local embedded DuckDB execution<br/>• Local SQLite metadata<br/>• Zero external egress / air-gap ready"]
end
subgraph CustomerGit["Customer Change Control"]
Repo["Customer Git Repository & CI/CD<br/>• Customer Approval Gate<br/>• Every PR reviewed & signed-off by Customer<br/>• Automated deployment on merge"]
end
end
subgraph TaleshapePerimeter["Taleshape Operations (Zero Direct Access)"]
Engineers["Taleshape Engineers<br/>• Hardened Workstations (FDE, Proton Pass)<br/>• E2EE Communications (Proton Mail)<br/>• Hardware / FIDO2 MFA<br/>• No SSH access to customer nodes<br/>• No customer database credentials"]
end
ClinicalDB <-->|"Local Queries Only (Never leaves VPC)"| ShaperApp
Engineers -->|"Submits Pull Requests (Code Only)"| Repo
Repo -->|"Deploys Code (Triggered by Customer Approval)"| ShaperApp
Key Architectural Boundaries
Section titled “Key Architectural Boundaries”- Zero External Egress: Shaper does not transmit diagnostic data, query text, telemetry, user accounts, or usage statistics to Taleshape or any external third-party servers.
- No SSH or Direct Shell Access: Taleshape engineers do not possess SSH keys, VPN tunnels, bastion credentials, or remote management backdoors to customer servers.
- No Database Access: Taleshape never receives credentials to upstream customer databases, data warehouses, object storage buckets, or analytical data stores.
- Change Management via Customer Pull Requests: All operational maintenance—including container updates, security patches, configuration files, and SQL macros—is delivered via Git Pull Requests. Customer engineers retain the unilateral authority to inspect, test, approve, or reject any change before deployment.
3. HIPAA Posture (Health Insurance Portability & Accountability Act)
Section titled “3. HIPAA Posture (Health Insurance Portability & Accountability Act)”Zero-PHI Architecture
Section titled “Zero-PHI Architecture”Under 45 CFR § 160.103, Protected Health Information (PHI) includes any individually identifiable health information held or transmitted by a Covered Entity or Business Associate.
- Taleshape does not create, receive, maintain, or transmit PHI during standard operations.
- Analytical queries run in-memory within the customer’s DuckDB engine inside the customer’s VPC.
- Taleshape systems, databases, and employees never touch patient data, clinical records, or medical identifiers.
Clean-Room Support Protocols
Section titled “Clean-Room Support Protocols”To ensure PHI is never inadvertently transmitted during enterprise support engagements, Taleshape enforces a strict Clean-Room Support Policy:
- Intake Scrubbing Requirement: Customers are instructed never to transmit raw patient data, medical record numbers (MRNs), names, dates of birth, or Social Security numbers in support tickets, emails, or issue trackers.
- Log & Query Sanitization: Before sharing error logs, schema definitions, or SQL queries with Taleshape for troubleshooting, customers must sanitize or mask all identifiers.
- Screen-Sharing Protocol: During live technical syncs (conducted via Google Meet or within the customer’s enterprise meeting tools), customers are required to use non-production environments with synthetic, obfuscated, or mock data. Taleshape personnel will never request control of screens displaying unmasked clinical systems.
- Incidental Disclosure SOP: If a customer inadvertently sends un-sanitized logs or screenshots containing PHI:
- Taleshape personnel immediately quarantine the communication.
- The data is permanently purged from all local caches, trash, and mail clients.
- Taleshape issues a formal confirmation to the customer’s security/privacy officer within 24 hours detailing the containment and permanent deletion.
Business Associate Agreement (BAA)
Section titled “Business Associate Agreement (BAA)”Although Taleshape does not routinely access PHI, enterprise healthcare InfoSec and legal teams standardly require a Business Associate Agreement (BAA) as a risk management safeguard.
Taleshape readily executes our standard BAA, which is customized specifically for software support vendors with zero planned PHI access:
- View our standard BAA template: Taleshape Business Associate Agreement (BAA).
- We can also review and execute customer-provided BAA templates during enterprise contracting.
4. GDPR Posture (General Data Protection Regulation)
Section titled “4. GDPR Posture (General Data Protection Regulation)”As an Estonian company, Taleshape OÜ is directly governed by European Union data protection regulations (EU Regulation 2016/679 - GDPR) and is subject to the regulatory oversight of the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon - AKI).
Division of Roles: Controller vs. Processor
Section titled “Division of Roles: Controller vs. Processor”- Taleshape as Data Controller: Taleshape acts as a Data Controller solely regarding our direct business relationships—such as corporate customer contact names, business email addresses, contract documentation, and billing records.
- Taleshape as Data Processor: In providing enterprise support for self-hosted Shaper instances, Taleshape does not process personal data from customer analytical datasets. Any transient operational metadata (e.g., system logs shared for debugging) is processed strictly under the customer’s documented instructions pursuant to a standard Data Processing Addendum (DPA).
International Data Transfers (US ↔ EU)
Section titled “International Data Transfers (US ↔ EU)”When contracting with US companies:
- Customer Analytical Data Remains in the US: Because Shaper is hosted in the customer’s own US cloud or on-premise infrastructure, analytical data and end-user data never leave the United States.
- Support & Commercial Communications: Business contact information and support correspondence exchanged between US customers and Taleshape OÜ in Estonia are safeguarded under standard contractual safeguards, including EU Standard Contractual Clauses (SCCs).
Technical & Organizational Measures (TOMs - Article 32 GDPR)
Section titled “Technical & Organizational Measures (TOMs - Article 32 GDPR)”Taleshape maintains comprehensive technical and organizational measures to safeguard all company data:
| Security Domain | Implemented Control |
|---|---|
| Endpoint Encryption | Full-disk encryption (AES-256) enabled across all workstations (LUKS / FileVault). |
| Identity & Authentication | Universal Multi-Factor Authentication (FIDO2 / Hardware Security Keys or Authenticator App). SMS 2FA is prohibited. |
| Credential Management | Mandatory use of Proton Pass for zero-knowledge, high-entropy unique credentials per service. |
| Encrypted Communications | Corporate email and calendar hosted on Proton Mail (Proton AG, Switzerland), featuring zero-access encryption and strong European privacy protections. |
| Code Supply Chain | Protected main branches, mandatory code review, cryptographically signed release tags (Sigstore Cosign), and SLSA Mode:MAX build provenance. |
| Data Minimization | No customer logs or operational data are stored persistently on developer workstations. |
| Breach Notification SLA | Documented procedure to notify supervisory authorities and affected customers within 72 hours of any confirmed personal data breach. |
5. SOC 2 & ISO/IEC 27001 Posture & Roadmap
Section titled “5. SOC 2 & ISO/IEC 27001 Posture & Roadmap”Why Shaper’s Architecture Reduces Vendor Risk
Section titled “Why Shaper’s Architecture Reduces Vendor Risk”Traditional SaaS SOC 2 and ISO 27001 assessments focus heavily on multi-tenant cloud vulnerabilities: cross-tenant database leakage, public cloud firewall configurations, and unauthorized remote access to hosted production databases.
Because Taleshape delivers an on-premise / private-VPC deployed solution, the critical physical, network, and hosting controls are governed directly by your own SOC 2 / ISO 27001 certified cloud infrastructure (AWS, Azure, GCP, or private datacenter). Taleshape does not host, store, or have network access to your analytical data.
Alignment with AICPA Trust Services Criteria (SOC 2)
Section titled “Alignment with AICPA Trust Services Criteria (SOC 2)”Taleshape’s internal controls and software development lifecycle are strictly aligned with the AICPA Trust Services Criteria:
- Security: Enforced code reviews, automated CI/CD security scanning (GitHub CodeQL SAST, Dependabot 7-day cooldown, Gitleaks secret scanning, Go vulnerability checking), mandatory workstation encryption, zero-trust secrets management.
- Confidentiality: Zero-PHI clean-room support policy, end-to-end encrypted corporate email (Proton Mail), zero-knowledge credential vaulting (Proton Pass).
- Availability: Git-based declarative dashboard configurations, deterministic single-binary architecture, client-side automated S3 backups and restore procedures.
Alignment with ISO/IEC 27001:2022 (ISMS Framework)
Section titled “Alignment with ISO/IEC 27001:2022 (ISMS Framework)”Taleshape structures its Information Security Management System (ISMS) in direct alignment with the ISO/IEC 27001:2022 standard, specifically mapping internal controls across all four Annex A control themes:
| ISO/IEC 27001:2022 Theme | Controls Implemented at Taleshape |
|---|---|
| A.5 Organizational Controls | Documented Information Security Policy, Clean-Room Support SOPs, transparent Third-Party Vendor Registry, 24-hour customer incident notification SLA, and continuous compliance monitoring. |
| A.6 People Controls | Clean-room support training, mandatory employee confidentiality agreements, strict prohibition of storing customer production data on local media, and secure offboarding procedures. |
| A.7 Physical Controls | Remote work device security standards, full-disk encryption (AES-256) on all developer hardware, and clean desk/clear screen protocols during video calls and remote work. |
| A.8 Technological Controls | Universal hardware/app MFA (FIDO2), zero-knowledge credential management (Proton Pass), end-to-end encrypted email (Proton Mail), static application security testing (CodeQL), cryptographic container signing (Sigstore Cosign), and SLSA Mode:MAX build provenance. |
Phased SOC 2 & ISO 27001 Audit Roadmap
Section titled “Phased SOC 2 & ISO 27001 Audit Roadmap”Taleshape is executing a structured, multi-phase roadmap toward formal third-party SOC 2 Type II attestation and ISO/IEC 27001 certification:
graph LR
P1["<b>Phase 1: Present (Q3 2026)</b><br/><b>Control Alignment & ISMS</b><br/>• InfoSec Policy Formalization<br/>• Clean-Room Support SOPs<br/>• ISO 27001 & TSC Mapping<br/>• SLSA Mode:MAX & Cosign Signing"]
P2["<b>Phase 2: Q4 2026</b><br/><b>Automation & Dual-Track Gap Review</b><br/>• Automated Compliance Monitoring<br/>• Workstation Encryption Auditing<br/>• Pre-Audit Gap Assessment"]
P3["<b>Phase 3: Q1/Q2 2027</b><br/><b>SOC 2 Type I & ISO Stage 1</b><br/>• Independent CPA / Auditor Review<br/>• Control Design Evaluation<br/>• <b>Formal Type I Attestation</b>"]
P4["<b>Phase 4: Late 2027</b><br/><b>SOC 2 Type II & ISO Stage 2</b><br/>• 3–6 Month Observation Period<br/>• Operational Effectiveness Testing<br/>• <b>Formal Reports & Certification</b>"]
P1 --> P2 --> P3 --> P4
- Phase 1: Control Formalization & Alignment (Current — Q3 2026):
- Formalization of corporate Information Security Policies, Incident Response Playbooks, and Clean-Room Support Standards aligned with AICPA TSC and ISO/IEC 27001:2022 Annex A.
- Automated CI/CD supply chain hardening with verifiable SLSA attestations.
- Phase 2: Automated Compliance Monitoring & Gap Review (Q4 2026):
- Integration with an automated compliance platform to continuously audit workstation encryption, GitHub branch protections, and employee access controls across both SOC 2 and ISO 27001 frameworks simultaneously.
- Comprehensive readiness assessment to address any control gaps prior to formal audit.
- Phase 3: SOC 2 Type I Attestation & ISO Stage 1 Audit (Target: Q1/Q2 2027):
- Engagement of an independent, accredited AICPA CPA firm / ISO registrar to evaluate control design and verify ISMS implementation.
- Phase 4: SOC 2 Type II Attestation & ISO Stage 2 Certification (Target: Late 2027):
- Successful completion of a 3-to-6 month observation period evaluating operational control effectiveness, culminating in our formal SOC 2 Type II report and accredited ISO/IEC 27001 certification.
6. Third-Party Sub-processor & Vendor Registry
Section titled “6. Third-Party Sub-processor & Vendor Registry”Taleshape maintains a transparent inventory of third-party vendors and sub-processors utilized in our operations. Under GDPR (Art. 28) and HIPAA, we ensure all sub-processors are bound by strict data processing and confidentiality agreements:
| Vendor / Provider | Entity & Location | Classification | Purpose in Support Relationship | PHI Access? |
|---|---|---|---|---|
| GitHub, Inc. (Microsoft) | USA | Sub-processor | Source code repository hosting, issue tracking, GitOps PR delivery for customers | NO |
| Proton AG (Proton Mail, Proton Pass) | Switzerland (EU adequacy) | Sub-processor / Tooling | Corporate email, calendar, and password manager. Protected by zero-access encryption | NO |
| Cal.com, Inc. | USA | Sub-processor | Scheduling technical syncs, onboarding calls, and support reviews | NO |
| Stripe, Inc. & Wise Payments Ltd. | USA / UK | Sub-processor | Invoicing, payment processing, and corporate billing records | NO |
| Hetzner Online GmbH | Germany (EU) | Infrastructure Vendor | Hosting Taleshape operational systems, and uptime monitoring infrastructure | NO |
| Xolo OÜ | Estonia (EU) | Corporate Processor | Estonian corporate accounting, tax filing, and administrative compliance partner | NO |
| Cloudflare, Inc. | USA / Global | Infrastructure Vendor | DNS routing, and public website and docs | NO |
7. Incident Response & Vulnerability Management
Section titled “7. Incident Response & Vulnerability Management”Taleshape maintains a formal security incident response process:
- Incident Severity Classification: Incidents are triaged based on impact (Low, Medium, High, Critical) with defined internal response SLAs.
- Customer Notification SLA: In the event of a security incident affecting customer support artifacts or an inadvertent disclosure of operational data, Taleshape commits to notifying the customer’s designated security contact within 24 hours.
- Regulatory Breach Notification: For any personal data incident falling under GDPR, Taleshape adheres to the mandatory 72-hour notification window to the Estonian Data Protection Inspectorate (AKI).
- Vulnerability Disclosure Policy: Security researchers and customers can report vulnerabilities privately via GitHub Private Vulnerability Reporting or directly to security@taleshape.com with standard PGP encryption.
8. Summary for InfoSec Evaluators
Section titled “8. Summary for InfoSec Evaluators”| InfoSec / Audit Question | Taleshape Answer |
|---|---|
| Does Taleshape have access to patient or clinical data (PHI)? | No. Shaper runs 100% in your private infrastructure. Taleshape has no database or network access. |
| Can Taleshape access our servers via SSH or VPN? | No. We maintain zero direct access. All updates and configuration changes are delivered as Pull Requests for your review. |
| Will Taleshape sign a Business Associate Agreement (BAA)? | Yes. We provide our tailored Standard BAA Template or can execute your enterprise BAA. |
| How does Taleshape protect communications and credentials? | We use Proton Mail (end-to-end encrypted) and Proton Pass (zero-knowledge vault) hosted in Switzerland. |
| What is Taleshape’s SOC 2 & ISO 27001 status? | Controls are aligned with AICPA TSC and ISO/IEC 27001:2022 Annex A. Formal SOC 2 Type I and ISO Stage 1 target is Q1/Q2 2027, followed by Type II and certification in late 2027. |
| Where is Taleshape incorporated? | Taleshape OÜ is incorporated in Estonia (European Union) and governed by EU GDPR under the Estonian AKI. |
For customized security questionnaires (SIG Lite, CAIQ, VSA, or custom vendor assessments), please contact our security team at security@taleshape.com.

