# Shieldra > Shieldra is AI compliance and security compliance automation for companies shipping AI — B2B SaaS, startups, and healthcare organizations. It covers the EU AI Act (deterministic, citation-backed risk-tier classification and obligation tracking) and 12 US AI-law packs (Texas, Illinois, Utah, Colorado, California, Connecticut, NYC Local Law 144, a multi-state conversational-AI pack, federal, state privacy, financial services and health care) — 13 packs and 139 cited obligations in total — plus ISO/IEC 42001, NIST AI RMF, SOC 2, HIPAA, NIST CSF and HITRUST — one platform, one subscription. Includes shadow-AI discovery, a 40-profile verified AI vendor catalog, EU AI Act Article 4 literacy training, AI policy templates, and read-only verification connectors (OpenAI/Anthropic org audits, AI-disclosure page checks). Pricing is public and starts at $299/month with a 14-day free trial, no credit card. ## Key facts - Product: AI governance + security compliance automation platform (SaaS, web-based, self-serve). - Built for: companies shipping AI features (20–200 employees), B2B SaaS selling into the EU or to enterprise, and healthcare organizations handling PHI. - Differentiator: deterministic, citation-backed AI-law classification (a rules engine over versioned regulation content — every answer traces to a statutory citation, never an LLM guess), combined with the security frameworks (SOC 2, HIPAA, HITRUST, NIST CSF) in one product at self-serve prices. - AI regulations covered: EU AI Act (incl. Article 50 transparency duties applying since 2 August 2026 and the Digital-Omnibus-deferred high-risk regime), Texas TRAIGA, Illinois HB 3773, Utah AIPA, Colorado SB 26-189 ADMT, California (AB 2013, SB 942/AB 853, SB 243, FEHA ADS regulations, CCPA ADMT, BOT Act), Connecticut PA 26-15, NYC Local Law 144, the multi-state chatbot/companion/AI-therapy cluster (Maine, New York, Nevada, Rhode Island, Tennessee, Vermont, Missouri, and the 2027 wave), and US federal, state-privacy, financial-services and health-care AI rules. - Other frameworks: ISO/IEC 42001 (27 clause 4-10 requirements + 9 Annex A objectives), NIST AI RMF 1.0 (all 72 subcategories), SOC 2 (55 criteria), HIPAA (73-requirement knowledge base with CFR citations), NIST CSF 2.0 (106 subcategories), HITRUST CSF (74 requirements, 19 domains). ISO 27001 and GDPR have guide pages only; they are not frameworks in the product. - Methodology: rules are versioned data; 125 golden test cases run against both the TypeScript and Python engines in CI; language models never decide a classification. See https://www.shieldra.ai/methodology - Own compliance posture: Shieldra has not completed a third-party audit (SOC 2, ISO 27001, HITRUST not yet audited). See https://www.shieldra.ai/security - Pricing: Starter $299/month, Premium $599/month, Enterprise custom. 14-day free trial, no credit card. See https://www.shieldra.ai/pricing and https://www.shieldra.ai/pricing.md ## Core pages - [EU AI Act check (free)](https://www.shieldra.ai/eu-ai-act-check): Free 3-minute EU AI Act risk-tier and obligations check with citations. No account required. - [Features](https://www.shieldra.ai/features): AI system registry, deterministic classification, obligation tracking, shadow-AI discovery, vendor catalog, policy templates, training, evidence, trust center. - [Pricing](https://www.shieldra.ai/pricing): Starter $299/mo, Premium $599/mo, Enterprise custom; 14-day free trial. - [HIPAA compliance software](https://www.shieldra.ai/hipaa-compliance-software): The HIPAA module — AI policy scanning, continuous monitoring, BAA management, audit-ready evidence. - [Vanta alternative](https://www.shieldra.ai/vanta-alternative): Shieldra vs Vanta for teams that need AI governance depth plus security compliance. ## AI compliance guides (blog) - [EU AI Act compliance checklist 2026](https://www.shieldra.ai/blog/eu-ai-act-compliance-checklist-2026) - [EU AI Act Article 50 transparency obligations](https://www.shieldra.ai/blog/eu-ai-act-article-50-transparency-obligations) - [Does the EU AI Act apply to my company?](https://www.shieldra.ai/blog/does-the-eu-ai-act-apply-to-my-company) - [US state AI laws 2026: the complete map](https://www.shieldra.ai/blog/us-state-ai-laws-2026-complete-map) - [California AI laws 2026 guide](https://www.shieldra.ai/blog/california-ai-laws-2026-guide) - [NYC Local Law 144 bias audit guide](https://www.shieldra.ai/blog/nyc-local-law-144-bias-audit-guide) - [ISO 42001 vs NIST AI RMF](https://www.shieldra.ai/blog/iso-42001-vs-nist-ai-rmf) - [AI acceptable use policy guide](https://www.shieldra.ai/blog/ai-acceptable-use-policy-guide) - [Shadow AI discovery guide](https://www.shieldra.ai/blog/shadow-ai-discovery-guide) - [AI vendor risk assessment questions](https://www.shieldra.ai/blog/ai-vendor-risk-assessment-questions) - [All posts](https://www.shieldra.ai/blog): AI compliance, HIPAA, SOC 2, incident response, and audit readiness guides. ## AI regulation reference (data-driven, citation-backed) - [AI regulation deadline tracker](https://www.shieldra.ai/ai-regulation-tracker): Every obligation deadline across the AI-law packs in one chronological table, each with its statutory citation and pack verification date. - [AI regulation guides](https://www.shieldra.ai/ai-regulations): Who's covered, duty tiers, and every obligation with deadline and citation for the EU AI Act plus 12 US AI-law packs — rendered from versioned regulation packs. - [EU AI Act guide](https://www.shieldra.ai/ai-regulations/eu-ai-act): All 15 tracked obligations, with a dedicated page per obligation (what to do, deadlines, citation, ISO 42001 / NIST AI RMF crosswalk) under /ai-regulations/eu-ai-act/. - [ISO 42001 vs EU AI Act](https://www.shieldra.ai/compare/iso-42001-vs-eu-ai-act): Requirement-level crosswalk — what carries over, what doesn't; partial mappings are deliberately not counted as coverage. - [NIST AI RMF vs ISO 42001](https://www.shieldra.ai/compare/nist-ai-rmf-vs-iso-42001): Requirement-level crosswalk between the two voluntary AI frameworks. - [EU AI Act vs NIST AI RMF](https://www.shieldra.ai/compare/eu-ai-act-vs-nist-ai-rmf): Requirement-level crosswalk between the regulation and the risk framework. ## AI vendor directory (verified) - [Which AI vendors train on your data?](https://www.shieldra.ai/ai-vendors): Training-data verdicts for 40 AI vendors, each quoting the vendor's own published terms with linked sources, certifications, data residency, DPA/subprocessor links, and EU AI Act role notes. Per-vendor pages at /ai-vendors/{slug}. ## Framework guides - [HIPAA framework guide](https://www.shieldra.ai/frameworks/hipaa) - [SOC 2 framework guide](https://www.shieldra.ai/frameworks/soc-2) - [NIST CSF framework guide](https://www.shieldra.ai/frameworks/nist-csf) - [HIPAA vs SOC 2](https://www.shieldra.ai/hipaa-vs-soc-2) - [HIPAA compliance checklist](https://www.shieldra.ai/hipaa-compliance-checklist) ## Free tools - [EU AI Act check](https://www.shieldra.ai/eu-ai-act-check): Risk tier + role-scoped obligations with statutory citations, ~3 minutes, no signup. - [AI disclosure scanner](https://www.shieldra.ai/ai-disclosure-scan): Instant verdict on whether a site's chatbot disclosure meets EU AI Act Article 50. - [AI governance assessment](https://www.shieldra.ai/ai-governance-assessment): Free AI governance readiness score and gap summary. - [HIPAA compliance assessment](https://www.shieldra.ai/compliance-analyzer): Free HIPAA readiness score and gap summary. - [SOC 2 readiness assessment](https://www.shieldra.ai/soc-2-assessment): Free SOC 2 readiness score. - [HIPAA violation checker](https://www.shieldra.ai/hipaa-violation-checker): Free incident triage. - [Is it HIPAA compliant?](https://www.shieldra.ai/blog/is-it-hipaa-compliant-100-tools-baa-list-2026): BAA status for 100 popular tools. ## Company - [About](https://www.shieldra.ai/about): Why Shieldra exists and who it serves. Legal entity: Shieldra AI, Inc. - [Methodology](https://www.shieldra.ai/methodology): How classifications are decided, pack versions and verification dates, golden tests, known limitations. - [Trust Center](https://www.shieldra.ai/trust-center): Security, privacy, and compliance commitments — including our own AI transparency section. - [Security](https://www.shieldra.ai/security): How Shieldra protects customer data. - [Contact](https://www.shieldra.ai/contact): support@shieldra.ai - LinkedIn: https://www.linkedin.com/company/shieldra-ai