← Back to AuditShield AI
📑 Enterprise Procurement

Standard Data Processing Agreement (DPA)

In Accordance with GDPR Article 28 & Standard Contractual Clauses (SCC)

1. Scope & Application

This Data Processing Agreement ("DPA") supplements the AuditShield AI Enterprise Terms of Service and applies to the processing of personal data in connection with the delivery of AuditShield AI compliance acceleration toolkits, Infrastructure-as-Code modules, and sovereign policy vaults.

2. Processing Roles

The purchasing enterprise acts as the Data Controller, and AuditShield AI acts as the Data Processor in relation to any minimal business contact data processed in the course of providing support services.

3. Security Measures (Technical & Organizational)

AuditShield AI implements state-of-the-art security controls in compliance with AICPA SOC 2 CC6.1–CC6.8 and ISO 27001:2022 A.8.24:

  • Cryptographic Ledgers: All audit actions are hashed with SHA-256 and chained into tamper-evident ledgers.
  • Airgap Transmission Protection: Customer infrastructure code is executed locally; zero customer production data is stored on AuditShield multi-tenant cloud storage.
  • Encryption: AES-256 encryption-at-rest and TLS 1.3 encryption-in-transit for all administrative portals.

4. Sub-Processor Notifications & Audits

AuditShield AI maintains a strict sub-processor policy. In the event of any material change to infrastructure sub-processors, enterprise clients will be notified via email 30 days prior to engagement.

Terms of Service Privacy Policy Checkout Home