Security & Compliance

ShieldAD Report™ is a read-only Active Directory audit platform built in Belgium. Every scan runs on-premises, every report is encrypted end-to-end, and zero data is retained on our servers — aligned with NIS2, ISO/IEC 27001, ANSSI, GDPR, CIS Controls v8 and DORA.

Why trust ShieldAD?

Three architectural guarantees, not just policy promises.

Read-only audits

Your Active Directory is never modified. ShieldAD performs 100% passive scanning: it reads configuration attributes and never writes to your domain.

End-to-end encryption

Every generated report is encrypted with AES-256. All communications, where applicable, use TLS 1.2 or higher.

Zero data retention

Your reports are not stored by Mandatory Shield Company. Scan data is deleted after export, and nothing leaves your infrastructure by design.

Compliance standards

ShieldAD maps its technical controls to the frameworks your auditors and regulators expect — without ever displaying a synthetic percentage score.

NIS2
Covered
EU Directive 2022/2555 — Critical entities
Technical controls map to NIS2 risk-management and incident-notification requirements for essential and important entities.
ISO/IEC 27001
Aligned
Security governance & access control
Report structure and control coverage align with ISO/IEC 27001 Annex A domains, including access control and incident management.
ANSSI
Aligned
French cybersecurity agency recommendations (R33, R72)
Kerberos, delegation and privileged-account checks follow ANSSI's Active Directory hardening recommendations.
GDPR
Compliant
Data protection compliance
ShieldAD analyzes technical AD configuration attributes only — no personal data is extracted, stored or transmitted during a scan.
CIS Controls
Integrated
Technical benchmark v8 (IG1/IG2/IG3)
Findings are mapped to CIS Controls v8 implementation groups for practical, prioritized remediation.
DORA
Covered
Operational resilience — financial entities
Access-management and resilience-testing evidence support DORA's ICT risk-management requirements for EU financial entities.

Security practices

Concrete engineering and governance measures behind every ShieldAD release.

NDA-protected delivery

Every on-site engagement starts with a signed non-disclosure agreement, protecting your Active Directory configuration and findings before any data is touched.

Integrity verification (SHA-256)

The ShieldAD executable's SHA-256 hash is validated together with your consultant, in person, before every scan — so you can be certain nothing was tampered with before launch.

Audit logging

Every scan is recorded and traceable, giving your team a clear operational history of ShieldAD activity.

On-device data storage

Scan results, findings and license data stay in a local folder on the machine you run ShieldAD from — nothing is synced to external servers or cloud storage.

Annual security reviews

Mandatory Shield Company runs an internal security audit of ShieldAD every year.

Shared responsibility

ShieldAD provides evidence and prioritization; your CISO remains the owner of the findings and remediation decisions.

Found a security vulnerability?

Contact us responsibly — we take every report seriously.

Response time: within 48 hours  ·  PGP key: available upon request

  • Description of the issue
  • Steps to reproduce
  • Potential impact
  • Your contact information

We will acknowledge receipt, work to fix the issue, and credit you in our security advisories.