Compliance

Compliance without
the chase.

Audit trails generated on every release. GDPR compliant by default. Compliance evidence your auditors can actually use — without chasing developers.

Most platforms make compliance your problem. Shaep generates audit trails automatically on every release — who changed what, when, and why. Security scans run in the pipeline. Compliance evidence is exportable, not something you have to reconstruct. Your auditors get what they need without engineering lifting a finger.

Audit trails on every release

Audit trails on every release

Every code change is tracked via Git history. Every deployment triggers platform-level audit events. Full traceability from code commit to production — exportable for auditors at any time.

  • Automatic audit trail generation
  • Full Git history per app
  • Platform-level deployment events
  • Exportable and API-accessible
Organisation-wide visibility

Organisation-wide visibility

See compliance status across all apps and teams from one dashboard. Who has access to what, which apps passed their last security scan, and where attention is needed.

  • Compliance posture per app
  • Access control overview
  • Security scan history
  • Budget and resource visibility
Compliance posture at a glance

Compliance posture at a glance

Track your compliance posture across frameworks — GDPR, ISO 27001, and more. See which controls are met, which are in progress, and what needs attention. Evidence is linked, not described.

  • Framework-mapped controls
  • Evidence linked to releases
  • Progress tracking per control
  • Audit-ready at all times

Frequently asked questions

How are audit trails generated? +

Every code change is tracked via Git history. Every deployment triggers platform-level audit events — who changed what, when, and why. Both are exportable and available via API.

What certifications do you have? +

GDPR compliant by default. ISO 27001 certification is in progress. We use 100% EU-owned infrastructure providers. A DPA is available on request.

How does the DPA work? +

A standard DPA is included on all plans. Enterprise customers can request a custom DPA tailored to their organisation.

Can we track costs per department? +

Yes. Resource usage data per app and per team. Finance sees what things cost, engineering doesn't have to report it.

Who are your subprocessors? +

Our infrastructure runs on Scaleway (France). We maintain a subprocessor list and notify customers of changes. Contact us for the current list.

Need compliance details?

We'll provide a DPA, walk through our audit trail, or answer your compliance questions.

Talk to us