Governance & compliance layer — access control, audit logging, compliance reporting, data residency. Answers for business leaders, no technical background required.
Last updated: 2026-07-09Shield is a governance and compliance layer for your AI infrastructure. It sits on top of your self-hosted AI stack (ODW.ai or other tools) and provides:
Think of Shield as the "compliance officer" for your AI stack — it makes sure everything is governed, auditable, and defensible to regulators and enterprise customers.
Regulated businesses face a fundamental tension:
Shield solves this by providing self-hosted governance that stays on your infrastructure. No cloud dependency. No telemetry leaving your servers. Full sovereignty.
Shield is designed for regulated SMBs (50–500 employees) in industries with compliance obligations:
The typical buyer is a technical founder, CTO, or IT lead who needs to demonstrate compliance to win enterprise customers but can't afford a full security team.
Not exactly. Shield is a governance and compliance layer — it's more specific than a general security product.
What Shield does:
What Shield does not do:
Shield governs what it can observe — access events, model invocations, data flows across your AI stack. It doesn't replace your firewall or antivirus.
The key difference is deployment model:
| Aspect | ODW.ai Shield | Vanta / Drata / Secureframe |
|---|---|---|
| Deployment | ✅ Self-hosted — runs on your infrastructure | ❌ Cloud SaaS — telemetry sent to vendor |
| Data sovereignty | ✅ Full control — no data leaves your servers | ❌ Vendor has access to your telemetry |
| Target market | Regulated SMBs who self-host AI | General compliance automation |
| AI-specific | ✅ Purpose-built for AI governance | ❌ General compliance, not AI-specific |
| Price | $299-$999/month | $10K-$50K+/year |
If you're self-hosting AI for sovereignty reasons, you can't send your infrastructure telemetry to a cloud compliance SaaS. That's the problem Shield solves.
No. Shield is model-agnostic and platform-agnostic. It works with:
Shield governs what it can observe. If your system emits access events, model invocations, or data flows, Shield can ingest and govern them.
"Governance" means control, visibility, and accountability over your AI stack:
Without governance, self-hosted AI is a black box. You don't know who's using it, what data they're accessing, or whether you're compliant. Shield gives you the governance layer to make self-hosted AI defensible.
Maybe. If you're already compliant and have manual processes for:
…then Shield might be redundant. But most SMBs don't have these processes — or they're manual, error-prone, and time-consuming.
Shield automates and centralizes these processes. Instead of spending days/weeks producing audit evidence, you can do it in minutes. Instead of manually checking configurations, Shield scans automatically and alerts on drift.
Even if you're already compliant, Shield can reduce the time and cost of maintaining compliance.
No. Shield is optional. You can use Desk, Voice, Vault, and other ODW.ai products without Shield.
However, Shield adds governance capabilities that are critical for regulated businesses:
If you're a regulated business, Shield is strongly recommended. If you're not regulated, you may not need it.
Shield provides enterprise-grade access control:
All access control is centralized in Shield — no need to configure permissions separately for each ODW.ai product.
Shield supports SSO via SAML 2.0 and OIDC (OpenID Connect):
Setup typically takes 15-30 minutes. Shield provides step-by-step guides for each provider.
RBAC (Role-Based Access Control): Permissions are assigned to roles, and users are assigned to roles.
ABAC (Attribute-Based Access Control): Permissions are based on attributes (user attributes, resource attributes, environment attributes).
Shield supports both. Most customers start with RBAC and add ABAC as their policies become more complex.
Yes. Shield can enforce MFA (multi-factor authentication) at the organization level or per role:
Supported MFA methods:
Shield provides centralized API key management:
API keys are scoped to specific actions and resources — no over-privileged keys.
Yes. Shield supports attribute-based policies that can restrict access based on:
These policies are enforced at the gateway level — if a request doesn't match the policy, it's rejected before it reaches the application.
Shield provides instant access revocation:
If you're using SSO (Okta, Azure AD, etc.), disabling the user in your identity provider automatically revokes access in Shield — no separate step required.
Yes. Shield provides real-time visibility into all access events:
Every access event includes:
| Feature | ODW.ai Shield | Typical Alternatives |
|---|---|---|
| Deployment | ✅ Self-hosted — full sovereignty | ❌ Cloud SaaS — telemetry to vendor |
| AI-specific | ✅ Purpose-built for AI governance | ❌ General compliance, not AI-specific |
| Price | $299-$999/month | $10K-$50K+/year |
| Setup time | ✅ Hours (guided workflows) | ⚠️ Days/weeks (manual configuration) |
| Evidence generation | ✅ One-click audit-ready packages | ⚠️ Manual collection (days/weeks) |
| Suite integration | ✅ Native ODW.ai integration | ❌ Requires custom integration |
| Model-agnostic | ✅ Works with any AI stack | ⚠️ Limited to specific platforms |
Shield competes on sovereignty + AI-specific governance, not just general compliance. If you're self-hosting AI for data residency, you need a self-hosted governance layer — that's Shield.
Vanta and Drata are excellent compliance automation platforms, but they have different design priorities:
| Aspect | ODW.ai Shield | Vanta / Drata |
|---|---|---|
| Deployment | ✅ Self-hosted | ❌ Cloud SaaS |
| Data sovereignty | ✅ Full control | ❌ Telemetry sent to vendor |
| AI-specific | ✅ Purpose-built for AI | ❌ General compliance |
| Target market | Regulated SMBs (50-500 employees) | Startups to enterprise |
| Price | $299-$999/month | $10K-$50K+/year |
| Scope | AI governance + compliance | Full compliance automation |
Choose Vanta/Drata if you need broad compliance automation (HR, IT, security, etc.) and don't have sovereignty requirements. Choose Shield if you're self-hosting AI and need sovereignty + AI-specific governance.
Configuration hardening means ensuring your AI stack meets security best practices:
Why it matters: Misconfigurations are the #1 cause of security breaches. Shield ensures your AI stack is hardened against common vulnerabilities.
Shield enforces data residency policies to ensure data doesn't leave your defined boundaries:
Example: A healthcare customer configures Shield to ensure PHI never leaves their on-premises infrastructure. If a user tries to send PHI to a cloud AI model, Shield blocks the request and alerts the admin.
Immutable audit logging means logs cannot be altered or deleted — they're tamper-proof:
Why it matters: Auditors need to trust that logs haven't been altered. Immutable logs provide that trust. If logs can be modified, they're not defensible in an audit.
Yes. Shield integrates with common SIEM and log aggregation tools via standard protocols:
Shield emits logs in standard formats (JSON, syslog) — no proprietary protocols. If your SIEM can ingest JSON or syslog, it can ingest Shield logs.
Yes. Shield supports multi-tenancy for Managed Service Providers (MSPs):
This allows MSPs to manage compliance for multiple SMB clients from a single Shield deployment.
Yes. Shield is model-agnostic and platform-agnostic. It governs:
Shield doesn't care what AI stack you're using — it governs what it can observe.
Shield logs all governance-relevant events:
All logs are immutable, tamper-proof, and retained according to your configured retention policy.
Retention is configurable and can be aligned to regulatory requirements:
Logs are automatically deleted after the retention period expires. You can also manually delete logs (e.g., if a customer requests deletion under GDPR).
Yes. Shield supports log export in standard formats:
You can export:
Exports are generated on-demand and can be downloaded via the admin console or API.
Shield provides one-click evidence generation for SOC 2 audits:
What used to take days/weeks now takes minutes. The evidence package is auditor-ready — you can hand it directly to your auditor.
Yes. Shield provides a read-only auditor view:
This allows auditors to verify compliance directly in Shield — no need to export data and send it externally.
Shield logs are cryptographically tamper-evident:
If an auditor questions log integrity, show them the hash chain verification report. This is cryptographically provable — not just a claim.
Yes. Shield provides real-time alerting for suspicious activity:
Alerts can be sent via:
Shield includes HIPAA-specific audit logging requirements:
Shield's HIPAA control mapping shows you exactly which HIPAA requirements are met by Shield's audit logging. You can generate a "HIPAA audit readiness report" to show your compliance officer or auditor.
Yes. Shield is built with security best practices:
Shield is designed to be the most secure component in your AI stack — because it governs everything else.
No. Shield is self-hosted on your infrastructure. ODW.ai has zero access to your data, logs, or configurations.
Unlike cloud compliance SaaS (Vanta, Drata), Shield doesn't send telemetry to a third party. Everything stays on your servers.
This is critical for sovereignty-focused organizations. You can't claim data sovereignty if your compliance tool is sending your data to a cloud vendor.
Shield is designed to be resilient:
In most cases, Shield going down does not affect your AI stack's availability — only its governance. Your users can still access the AI, but access control and audit logging are temporarily disabled.
Yes. Shield enforces encryption policies:
Shield also enforces encryption policies across your AI stack — e.g., it can detect if your vector database is not encrypted at rest and alert you.
Shield provides data leak prevention (DLP) capabilities:
Example: A user tries to send a prompt containing PHI to OpenAI's API. Shield detects the PHI, blocks the request, and alerts the admin.
Shield is compatible with GDPR and provides tools to help you meet GDPR requirements:
Shield's GDPR control mapping shows you exactly which GDPR articles are addressed by Shield. You can generate a "GDPR compliance report" for your DPO or regulator.
Shield follows industry best practices for security:
We're pursuing SOC 2 Type II certification for Shield itself (expected late 2026). For now, we provide a security whitepaper and can answer specific security questions from your IT team.
Yes. Shield supports air-gapped deployment (no internet access):
Air-gapped deployment is common for government contractors, military, and high-security environments.
Shield includes pre-built control mappings for:
Additional frameworks (FedRAMP, PCI DSS, NIST) are planned for future releases. You can also create custom frameworks if needed.
Shield provides a control mapping that shows which SOC 2 Trust Services Criteria are addressed by Shield:
For each control, Shield shows:
Target: 80% of SOC 2 controls addressed by Shield at MVP, 95% by month 18.
Shield helps you meet the controls required for SOC 2, but it doesn't guarantee audit passage (no tool can honestly claim this).
What Shield does:
What you still need:
Yes. Shield provides HIPAA-specific features:
Shield helps you meet the technical safeguards required by HIPAA (access control, audit controls, integrity, transmission security). You still need to address administrative and physical safeguards separately.
Yes. Shield provides GDPR-specific features:
Shield helps you meet the technical and organizational measures required by GDPR (Article 32). You still need to address legal and procedural requirements separately.
Yes. Shield supports custom frameworks:
This is useful for:
Shield provides a gap analysis feature:
This gives you a clear roadmap for achieving compliance — no more guessing what you're missing.
Yes. Shield can generate executive-level compliance reports:
These reports are designed for non-technical audiences — they show the big picture without getting into the weeds.
Shield offers three deployment options:
For most customers, SaaS is the fastest path. For regulated industries (healthcare, legal, government), we recommend private cloud or on-premises.
Setup time depends on your deployment:
Most customers are live within a week. Complex deployments (multi-tenant, custom integrations) may take 2-3 weeks.
For SaaS: Minimal. The admin console is designed for non-technical users (compliance officers, IT managers). You can configure policies, view audit logs, and generate reports without writing code.
For private cloud or on-premises: Yes. You need someone who can manage Docker/Kubernetes, configure networking, and monitor infrastructure. This is typically a DevOps engineer or IT consultant.
Day-to-day operation (reviewing logs, generating reports, adjusting policies) is non-technical for all deployment modes.
Shield is lightweight:
| Component | Minimum | Recommended |
|---|---|---|
| CPU | 2 cores | 4+ cores |
| RAM | 4 GB | 8+ GB |
| Storage | 50 GB SSD | 200+ GB SSD (depends on log volume) |
| OS | Linux (Ubuntu 20.04+, RHEL 8+) | Ubuntu 22.04 LTS |
| Database | PostgreSQL 16+ | PostgreSQL 16+ (managed) |
Shield runs as a set of Docker containers — no special hardware required. For high-availability deployments, we recommend Kubernetes with 3+ replicas.
Yes. Shield provides migration tools:
Migration typically takes 1-2 weeks. We provide migration guides and support for common tools (Vanta, Drata, Secureframe).
Shield is configured via the admin console (web-based UI):
No code required. All configuration is done through the UI. For advanced users, Shield also provides a CLI and API for automation.
Yes. Shield includes a preview mode:
We recommend testing thoroughly before going live. Most customers spend 1-2 days testing in dry-run mode.
For SaaS: Updates are automatic. We deploy new versions without downtime (rolling updates).
For private cloud or on-premises: Updates are performed via Docker/Kubernetes:
Total update time: <5 minutes (plus downtime during restart for non-rolling updates).
Shield pricing is based on deployment mode and features:
| Tier | Price | Includes |
|---|---|---|
| Starter | $299/month | SaaS, basic access control, audit logging, 1 compliance framework |
| Professional | $699/month | SaaS or private cloud, all features, all compliance frameworks, priority support |
| Enterprise | $999+/month | On-premises, all features, multi-tenant (MSP), dedicated support, custom SLA |
Additional costs:
Yes, significantly. Vanta and Drata typically cost $10K-$50K+/year. Shield costs $3,600-$12,000/year — 3-10x cheaper.
And Shield is self-hosted — you get full sovereignty. Vanta/Drata are cloud SaaS — you send them telemetry.
Of course, Shield is more focused (AI governance) while Vanta/Drata are broader (full compliance automation). But if you're self-hosting AI and need sovereignty, Shield is the only option.
No hidden costs. The total cost of ownership includes:
That's it. No setup fees, no surprise charges. Infrastructure costs (if self-hosting) are separate — you pay for your own servers/cloud.
Yes. We offer a 14-day free trial of the Professional tier. No credit card required.
During the trial, you can:
At the end of the trial, you can subscribe or downgrade to the free tier (limited features).
We accept:
Invoicing is available for annual subscriptions. Contact us for details.
Yes. We offer a 30-day money-back guarantee. If you're not satisfied within the first 30 days, contact us for a full refund — no questions asked.
After 30 days, you can cancel anytime. You'll continue to have access until the end of your billing period, but no refund is provided for partial months.
Yes and no. Shield is available as a standalone product or as part of the ODW.ai suite bundle:
The suite bundle includes Shield at a 20-30% discount compared to purchasing separately. Contact us for bundle pricing.
Shield scales horizontally:
For very large deployments (10,000+ users), we recommend Kubernetes with auto-scaling and a managed PostgreSQL database.
If Shield goes down, your AI stack continues to operate (in fail-open mode):
For high-availability deployments, we recommend:
Shield includes a monitoring dashboard:
You can also export metrics to external monitoring tools (Prometheus, Grafana, Datadog) via standard protocols.
Shield data is stored in PostgreSQL. Back up the database using standard PostgreSQL tools:
Shield provides backup guides and scripts for common deployment modes (Docker, Kubernetes, on-premises).
Yes. Shield can govern multiple AI stacks from a single deployment:
Each AI stack is configured as a "source" in Shield. Shield ingests logs from all sources and applies unified policies.
Shield is designed to be intuitive, but we provide training resources:
Most teams are productive within 2-4 hours of training. The admin console is particularly intuitive — no technical skills required for day-to-day operation.
Yes. Shield is highly configurable:
For advanced customization, Shield provides a plugin system (Python) — write custom policy evaluators, log processors, or report generators.
Shield integrates natively with all ODW.ai products:
If you're using the ODW.ai suite, Shield integration is automatic — no separate configuration required.
Shield integrates with non-ODW.ai tools via standard protocols:
If your AI tool can emit logs via one of these protocols, Shield can ingest and govern them.
Yes. Shield integrates with common SIEM tools:
Shield emits logs in standard formats (JSON, syslog) — no proprietary protocols. If your SIEM can ingest JSON or syslog, it can ingest Shield logs.
Yes. Shield supports SSO via SAML 2.0 and OIDC:
Setup typically takes 15-30 minutes. Shield provides step-by-step guides for each provider.
Yes. Shield can create tickets in your ticketing system via webhooks:
This allows your team to track and resolve compliance issues in the same system they use for other work.
Yes. Shield supports multi-channel notifications:
You can configure different notification channels for different alert severities (e.g., email for low-severity, PagerDuty for critical).
Yes. Shield provides a REST API for programmatic access:
The API is fully documented (OpenAPI/Swagger) and supports authentication via API keys or OAuth 2.0.
Shield is powerful, but it has limitations in v1.0:
Planned for v1.1 (Q4 2026). We're adding pre-built control mappings for:
In the meantime, you can create custom frameworks for these requirements using Shield's custom framework builder.
Planned for v1.2 (Q1 2027). Incident response automation will include:
This is a high-priority feature for enterprise customers.
Not in the current roadmap. Shield is focused on self-hosted AI governance. Cloud workload protection (CWPP/CSPM) is a different category with different requirements.
If you need cloud workload protection, we recommend using a dedicated tool (e.g., Wiz, Orca, Prisma Cloud). Shield can integrate with these tools via APIs and webhooks.
Key milestones:
Roadmap is subject to change based on customer feedback. Contact us for the latest roadmap or to request features.
Shield is not the right fit if:
No. No tool can honestly guarantee audit passage. Shield helps you meet the controls required for compliance, but audit passage depends on many factors:
Shield reduces the time and cost of compliance by 50-80%, but it's not a magic button. You still need to do the work.
Three paths:
odw.ai/shield to sign up for a free trial or book a demo.