Shield Desk
  • Security Architecture
  • Use Cases
  • FAQ
  • About
Book a Demo
Security ArchitectureUse CasesFAQAboutBook a Demo
FAQ

Answers for security and compliance teams

The questions we hear most from the people who evaluate Shield Desk. If yours is not here, our team will answer it directly.

No. Shield Desk operates on a zero-knowledge architecture: your encryption keys are generated on your device and never leave it in unprotected form. Files are encrypted before they reach our servers. We host and operate the infrastructure, but the data itself is opaque to us. Our staff cannot decrypt your files, read your messages, or access your account contents. This is enforced by the architecture, not by internal policy.

In transit, all connections use TLS 1.3, the current industry standard. In storage, every file is encrypted client-side with AES-256-GCM before upload, using keys only you hold. What lands on our servers is ciphertext, so even if our infrastructure were compromised, your data remains unreadable. Backups inherit the same encryption, so the protection extends to disaster recovery as well as primary storage.

The Key Vault is the client-side component that protects your encryption keys. Your master key is derived from your password using Argon2id, a memory-hard key derivation function designed to resist brute-force attacks even by well-resourced adversaries. The vault never transmits your password or master key to Shield Desk. On supported devices, vault contents can be additionally protected by hardware security: Secure Enclave on Apple devices, TPM on Windows, and hardware keys via WebAuthn.

No, we cannot recover your keys. That is the cost of true zero-knowledge: if Shield Desk could recover your keys, so could anyone who compelled us to. We offer three recovery options that you control:

  • Recovery key: a one-time recovery code generated when you set up your account, which you store securely in a password manager, safe, or secure offline location.
  • Trusted custodians, using Shamir's Secret Sharing: split your recovery capability across 3 to 5 named colleagues, where any 2 to 3 of them together can help you recover access.
  • Hardware-backed recovery: pair a YubiKey or equivalent at setup as a physical recovery factor.

Firms with regulatory obligations can also configure escrow with a designated legal custodian. We strongly recommend setting up at least one recovery method before storing important data.

Real-time communications use end-to-end encryption with the Signal Protocol or an equivalent forward-secrecy design. Each message session generates fresh keys, so even if a future key were compromised, past messages remain protected, a property known as forward secrecy. Calls are encrypted media streams negotiated directly between participants. Shield Desk relays the metadata necessary to establish connections but cannot access call content or message contents at any point.

Shield Desk is designed to meet:

  • UK GDPR and EU GDPR, including data subject rights, breach notification, and lawful basis. Data Processing Agreements are signed as standard, and Standard Contractual Clauses and the UK IDTA are available for international transfers.
  • CCPA and CPRA, for California residents and businesses with Californian customers.
  • HIPAA, with Business Associate Agreements available for US healthcare contexts.
  • NHS DSPT and Caldicott principles, for UK healthcare deployments.
  • SRA confidentiality obligations, relevant for UK law firms. The architecture supports the absolute confidentiality duty by ensuring only the firm holds keys.

Compliance is the floor, not the ceiling. The zero-knowledge architecture gives firms a structurally stronger position than compliance-only platforms.

Full control. You can export all your data at any time in standard formats. You can permanently delete files, conversations, or your entire account, and because we cannot decrypt your data, deletion means cryptographic erasure: even our backups become permanently unrecoverable. You set retention periods per matter or per data room. You control who has access and revoke it instantly. Audit logs of all data activity are available for export to support your own compliance records.

Integrations follow the principle of least privilege. Each integration receives only the specific permissions required for its function and operates on encrypted data wherever architecturally possible. For integrations that must access plaintext, for example document preview generation, processing occurs in isolated environments that you authorise per matter and that retain no data after the operation completes. We publish a current list of sub-processors and notify customers of any additions in advance. You can disable any integration at the account level.

Multi-factor authentication is available via email-based One-Time Passcodes, providing an additional layer of security beyond your password. Session tokens are securely managed, short-lived, and designed to prevent exfiltration. Failed authentication attempts are rate-limited to protect against brute-force attacks.

Shield Desk protects against vendor-side threats: server breaches, insider threats within our team, cloud-provider access, AI vendors training on your data, and legal compulsion directed at us. We cannot be made to surrender plaintext we never had access to.

Shield Desk does not replace endpoint security. If your device is compromised by malware while your vault is unlocked, an attacker on that device has the same access you do. No platform, ours or any other, can prevent that. We recommend pairing Shield Desk with current endpoint protection, OS updates, and full-disk encryption. We believe stating these limits clearly is part of earning your trust.

Your data remains yours, in encrypted form, regardless of what happens to Shield Desk. Because we operate on zero-knowledge architecture, an acquirer or successor entity inherits ciphertext they cannot decrypt, so they cannot weaponise the data even if they wished to. Our commitments:

  • A minimum 90-day data export window in any wind-down scenario.
  • Source code escrow on Enterprise contracts.
  • A published continuity plan that customers can review under NDA.
  • Investor and shareholder agreements that include change-of-control clauses protecting the architectural commitments published here.

Still have questions?

Book a demo and put your hardest questions to our team. We will walk through the architecture and your specific compliance requirements.

Book a demo
Shield Desk

Encrypted collaboration for teams that cannot afford to be seen.

Product

Security ArchitectureUse CasesBook a Demo

Company

AboutFAQContact

Legal

Privacy PolicyTerms of Servicetrevor@getshielddesk.com
© 2026 Shield Desk Ltd. All rights reserved.Zero-knowledge, end-to-end encrypted. United Kingdom.