Security & Trust

Last updated: June 2026

Our approach

AIShield365 is a complimentary AI-governance assessment tool from Patriot Consulting. We built it to help security leaders move quickly without asking them to trust us with more than is necessary: we collect the minimum data required to generate your package, we are explicit about every third party that touches it, and we never sell your information. This page describes how AIShield365 protects your data and where that data is processed.

How we handle your data

  • All traffic to AIShield365 is served over HTTPS (TLS) in transit.
  • Your survey answers are sent to Anthropic's Claude API to generate your policy document. We do not send your email address to Anthropic.
  • We collect your email address only to deliver your package and, with your consent, to send occasional governance updates. You can unsubscribe at any time.
  • The survey form is protected against automated abuse using Cloudflare Turnstile.
  • Your governance package is delivered to your email through a unique download link generated for your submission.

Full detail on collection, use, retention, and your rights lives in our Privacy Policy.

Subprocessors — where your data is processed

AIShield365 relies on the following third-party services. Each operates under its own security and privacy program:

VercelApplication hosting and encrypted file/object storage
Twilio SendGridDelivery of your governance package by email
AnthropicAI generation of your NIST AI RMF, ISO 42001, and EU AI Act policy document
CloudflareTurnstile bot / abuse protection on the survey form
GoogleAdvertising and conversion measurement

Compliance & certifications

We want to be precise about what AIShield365 is and is not. The framework labels in your generated policy map your selected controls to the NIST AI Risk Management Framework (AI RMF 1.0), the NIST Cybersecurity Framework, the Annex A controls of ISO/IEC 42001:2023, the international standard for an AI Management System (AIMS), and the articles of the EU AI Act (Regulation (EU) 2024/1689). These are alignment mappings to help you structure your governance — they are not an audit, attestation, or certification of your environment.

The EU AI Act needs its own caveat, because it is the one reference here that is binding law rather than a framework you choose to align to. Where a control cites an article, the claim is narrow: this technical control produces evidence you would need when demonstrating that obligation. It is not a legal opinion, a conformity assessment, CE marking, or a Fundamental Rights Impact Assessment under Article 27. Two determinations in particular are legal questions AIShield365 does not answer for you: whether a given system is high-risk under Annex I or Annex III, and whether you are acting as a provider or a deployer of it — the two roles carry different obligations, and most of the controls in the survey are deployer-side (Article 26, plus the Article 4 AI-literacy duty that reaches both). Take the Act itself, and your own counsel, as the authority: Regulation (EU) 2024/1689 on EUR-Lex.

The ISO/IEC 42001 distinction matters especially: unlike the NIST AI RMF, which is a voluntary framework you align to, ISO/IEC 42001 is a standard an organization can be certified against by an accredited certification body. AIShield365 produces a mapping showing which Annex A controls your selected technical controls help evidence. It does not produce a Statement of Applicability, run an AI system impact assessment, operate a management system, or constitute any step of a certification audit — and a real AIMS covers management-system clauses and process controls that no endpoint configuration can satisfy.

AIShield365 itself does not currently hold SOC 2, ISO 27001, ISO 42001, or FedRAMP certification, and we do not represent that it does. Organizations that require certified, audited, or fully managed AI governance — including independent control validation and deployment — should engage Patriot Consulting's SecureShield365 managed service.

Recommendations require your review

The policy and configuration files AIShield365 generates are recommendations based on the selections you make. Review and test them against your own environment and change- management process before deploying. Patriot Consulting is not responsible for changes applied without review.

Report a security concern

If you believe you have found a security issue in AIShield365, please tell us so we can address it. Email [email protected] with the details. We appreciate responsible disclosure and will respond as quickly as we can.

Contact

Patriot Consulting Technology Group LLC
Email: [email protected]