Shapes security and compliance

HR leaders handle some of the most sensitive data in the business. Shapes makes sure your data stays protected through continuous audits, strict access controls, and privacy safeguards built into every layer of the platform.

Trusted by

We meet the standards that matter

GDPR

GDPR-ready

Built with European data protection requirements at the core, not retrofitted in.

SOC2
TYPE II

SOC2 TYPE II

Independently audited across security, availability, and confidentiality controls.

ISO
27001

ISO 27001

Information security management certification

ISO
42001

ISO 42001

AI management systems certification

Your data, 


locked down

Once Shapes is connected to Claude, a single prompt does all the heavy lifting. Query your org, spot anomalies, generate instant insights and build dynamic presentations.

Built rigorously, 
end-to-end

Security isn't just about encryption. It's how we manage access, ship changes, and track every asset in our system.

Access control

Your data is on a strict need-to-know access level and reviewed regularly. Only the right people see your data.

Change management

Every system change is formally reviewed and tested before it goes live. No single person has unchecked control.

Asset management

Every asset is inventoried, classified by sensitivity, and disposed of securely when no longer needed.

Responsible AI, 


by default

AI is at the core of Shapes — so we take its governance seriously. Your data is never used to train off-the-shelf models, never shared across tenants, never exposed without your explicit permission. The third-party models and APIs we work with are held to the same standards. Your data is your intellectual property. We treat it that way.

Want the full technical picture?

Audit reports, detailed controls, documentation for your IT or legal team — it's all in our Trust Center.