Trust center
Shape Technology security and compliance
Security information for Shape Technology's use of Fi. Fi is operated by CellectAI Inc.
Security answers
Current operating status
Does Shape Technology have a SOC 2 report?Current
Cellect is preparing for an initial SOC 2 Type I examination of its product environment and supporting production systems. Fi is currently Cellect's only product and is therefore the product in the present examination scope. No report has been issued, and Cellect does not represent itself as SOC 2 compliant or certified.
Who operates Shape Technology?Current
CellectAI Inc is currently owner-operated with no employees or contractors holding production access. Controls are designed for that actual operating model rather than assuming a larger security organization.
Where is Shape Technology hosted?Current
Cellect's product environment runs on Cellect-managed infrastructure at a restricted-access facility in the United States. Fi is currently the only product in that environment. Detailed network and physical-location information is shared only when appropriate during a security review.
How is physical access restricted?Verifying
The physical-control design restricts building and equipment-area access to authorized people, with Cellect's owner currently the only person authorized for production equipment. The current evidence review is validating entry controls, inspection records, visitor handling, and environmental safeguards before this control is presented as verified.
How is customer access separated?Current
Cellect's current product, Fi, applies organization, company, project, and capability-level authorization. A user without an explicit resource grant cannot view that resource, and administrative routes require elevated authorization. New products must define and test equivalent access boundaries before handling customer data.
How are users authenticated?Current
Cellect product access currently uses centralized identity and short-lived application sessions. Fi is the current implementation. Administrative access is distinct from ordinary customer access.
Type I preparation
Readiness work in progress
These items are part of the current readiness plan and remain incomplete.
Document access
Restricted documents
Approved policies and available internal documents are shared after manual review. Planned reports are clearly labeled and cannot be downloaded.