Routed In Shield logo
Privacy Security · Guardrails Policy

Routed In Shield

Routed In Shield is a compliance and risk platform from a Latvian security firm. It manages NIS2, ISO 27001, ISO 42001, GDPR and SOC 2, with automated risk assessments, AI-generated policies and cloud monitoring across major providers.

Active Subscription No public API Verified by Guidaio
Overview

What is Routed In Shield?

Routed In Shield is the compliance and governance product of Routed In, a small cybersecurity and DevOps firm based in Latvia. The company sells four lines — Security, Shield, Development and DevOps — and Shield is the one that turns regulatory obligations into a managed, largely automated workflow. Its stated promise is automated compliance, risk management and security for modern enterprises, and it displays five frameworks side by side: NIS2, ISO 27001, ISO 42001, GDPR and SOC 2. Covering ISO 42001, the management standard for artificial intelligence, alongside the classic four is still uncommon.

Six capabilities are published. Multi-framework compliance handles all five standards from one platform. Automated risk assessment combines continuous monitoring, vulnerability scanning, cloud security analysis and threat intelligence. Dynamic policy management generates policies with AI and refreshes them as regulation and security posture evolve. DNS and email intelligence maps subdomains, analyses DNS records and rates email security posture. Cloud security monitoring embeds Cloud Custodian to check AWS, Azure and GCP environments in real time. Real-time dashboards serve both executives and engineers, integrate the Graylog SIEM and produce automated reports. The working application, hosted on a separate subdomain, exposes matching modules for controls, assets, tasks, incidents, standards and an audit centre.

The vendor positions itself for regulated industries and names finance, healthcare and SaaS among its results. Around the platform it sells priced engagements: penetration testing, gap assessments, extra frameworks or cloud providers, custom integrations and vCISO hours.

One caveat shapes everything a reader can verify. The public site is a JavaScript application that ships barely three kilobytes of markup and loads its editorial content from a hosted backend. Without running scripts there is no readable page at all, unknown addresses return the home page rather than an error, and there is no sitemap. Much of what the company says about itself — certifications, partners, case studies — is therefore absent from anything a visitor or a search engine can inspect directly.

What it does

  • Manage NIS2, ISO 27001, ISO 42001, GDPR and SOC 2 compliance from a single platform
  • Run continuous risk monitoring with automated vulnerability scanning and threat intelligence
  • Generate security policies with AI and update them automatically as regulation changes
  • Monitor cloud compliance in real time across AWS, Azure and GCP through Cloud Custodian
  • Map subdomains, analyse DNS and assess email security posture
  • Track executive and technical dashboards fed by Graylog SIEM, with automated reporting
  • Buy penetration testing, gap assessments and vCISO hours as priced add-on engagements
Audience

When to use Routed In Shield / When not to

A quick filter to help you decide if Routed In Shield is the right fit.

When to use Routed In Shield

  • European small and mid-sized companies that must demonstrate NIS2 or ISO 27001 readiness without hiring a full compliance team
  • Organisations of roughly 1 to 50 employees, the bracket the entry tier is explicitly written for
  • Teams with no full-time security officer, who can buy vCISO hours by the hour as an add-on
  • Engineering teams running multi-cloud estates on AWS, Azure and GCP that need continuous configuration checks
  • Companies in finance, healthcare and SaaS, the three sectors the vendor names when it describes its results

When not to use Routed In Shield

  • Buyers who need to embed compliance data into their own toolchain, since the product exposes no API and publishes no technical documentation
  • Anyone who requires published contractual documents before signing, as the site has no terms of service, no privacy policy and no data processing agreement
  • Procurement teams that must compare a complete published price list, because only the add-on services carry firm public figures
  • Mobile-first users, as there is no iOS or Android application and no browser extension
  • Organisations outside the European Union chasing SOC 2 alone, since the vendor's centre of gravity is clearly EU and Latvian regulation
Get started

How to use Routed In Shield

A typical end-to-end flow, from setup to results.

  1. Open the Shield page on the vendor's site, where the product, its five frameworks and its six capabilities are presented
  2. Follow the View Pricing Plans anchor to the pricing section further down the same page
  3. Read the add-on table, which lists the firmly priced engagements: extra frameworks, penetration testing, gap assessment, extra cloud provider, custom integration and vCISO hours
  4. Use Schedule a Consultation or the home page contact form to reach the vendor, since no self-service sign-up is documented
  5. Agree the scope directly with the vendor: which of the five frameworks apply, how many employees, how many cloud providers
  6. Request the contractual documents in writing, because no terms, privacy policy or data processing agreement is published
  7. Once contracted, go through the onboarding step the application provides
  8. Connect the AWS, Azure or GCP accounts that Cloud Custodian will monitor
  9. Wire the Graylog SIEM feed so the executive and technical dashboards receive events
  10. Review generated policies and risk assessments, then work the resulting controls and tasks in the platform
Quick read

Pros & Cons

Pros

  • Five major frameworks handled together, including ISO 42001 for AI management systems, which few competitors cover
  • Six add-on services carry firm published prices in euros, unusual in a market that almost always quotes privately
  • Named, verifiable integrations rather than vague claims: Cloud Custodian, Graylog, AWS, Azure and GCP
  • Genuine European footing, with national law (Latvia's NKDL) taken into account alongside GDPR
  • vCISO time sold by the hour, which suits a company with no full-time security officer
  • The interface is offered in English and Latvian
  • The underlying application is real and broad, with modules for controls, assets, incidents, standards and audit

Cons

  • No legal documentation whatsoever: the terms, privacy and cookie links in the footer lead nowhere
  • The plan grid cannot be verified, as its display depends on a backend flag and the only tier present in the code is an error fallback
  • The site renders entirely in JavaScript, publishing barely three kilobytes of markup and no indexable text
  • Every unknown address returns the home page instead of an error, and there is no sitemap, so nothing can be confirmed by browsing
  • No product API and no public technical documentation
  • Contact details on the main site were never corrected from the template: an undeliverable address and a fictional telephone number
  • No named certification, no named customer and no social media presence, despite sections built for all three
Pricing

Pricing & Plans

There is no free plan and no free trial. Pricing is published in euros, but only partially. Six add-on services carry firm, unconditional figures: an additional compliance framework at 1,000 EUR per month, penetration testing at 8,000 EUR one-time, a gap assessment at 5,000 EUR one-time, an additional cloud provider at 1,000 EUR per month, a custom integration at 3,500 EUR setup plus 500 EUR per month, and additional vCISO hours at 225 EUR per hour. The subscription tiers themselves could not be confirmed: the plan grid is displayed only when the vendor's backend enables it, and the single tier written into the site's code — a Starter plan at 2,950 EUR per month for 1 to 50 employees and two frameworks — is an error fallback shown when the real plans fail to load. It should not be read as an advertised price. The entry price is therefore not publicly verifiable, and prospective buyers should request a written quotation.

Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Routed In Shield handles your data.

GDPR overview

A distinction matters here. GDPR appears on this site as one of the five frameworks the product helps customers comply with, alongside NIS2, ISO 27001, ISO 42001 and SOC 2. It is not a claim about Routed In's own compliance. The vendor states it prepares documentation in line with EU and Latvian regulation, naming GDPR and the National Cybersecurity Law (NKDL), but that describes a service delivered to clients. On its own account the company publishes no privacy policy, names no data protection officer and designates no representative. The contact form is backed by Supabase and Google Tag Manager loads on every page, yet no notice explains either. The company is established in Latvia, therefore inside the EU.

Who owns the data?

Nothing is published on this point. Routed In has no terms and conditions: the Terms of Service, Privacy Policy and Cookie Policy links in the site footer all point to an empty anchor, and the matching paths simply return the home page. The same three dead links appear on the company's secondary landing page. As a result there is no published statement about who owns customer data, what Routed In may do with it, or which third parties may receive it. Anyone evaluating the product should obtain these commitments in writing before sending any data, because at the time of review no public document defines them.

Reuse rights

No contractual document is published, so the site says nothing about whether customers may reuse, export or redistribute the data and reports the platform produces. Shield generates policies, risk assessments and executive reports, and those outputs would normally be the customer's to use freely, but that is an assumption rather than a published right. There is likewise no statement on licence, on retention of derived material, or on what happens to reports after an account closes. These terms have to be negotiated directly with the vendor.

Data retention & training

Retention summary
No retention information is published. Routed In has no privacy policy and no terms of service, so the site states no retention period, no anonymisation practice and no deletion procedure for customer data, findings or generated reports. Nor is there any statement about what happens to the data once an engagement ends. For a platform that concentrates vulnerability scans, risk assessments and cloud configuration findings, this is a material gap: those records are precisely the ones an organisation would want deleted on a defined schedule. Retention terms need to be agreed contractually with the vendor before onboarding.

Hosting summary

Nothing is published about data hosting. There is no security page, no trust centre and no privacy policy, so no jurisdiction, no data centre location and no hosting provider is stated for customer data. The vendor is established in Latvia, hence inside the European Union, but that is a fact about the company rather than a commitment about where data resides. The AWS, Azure and GCP names that appear throughout the product description refer to the customer's own cloud environments that Shield monitors, not to the vendor's infrastructure, and should not be read as a hosting statement. Technical traces of the public website show a hosted backend service, a Cloudflare content network and Google Workspace mail, but these describe the marketing site rather than the platform, and none of them is presented as an engagement. Hosting arrangements must be established directly with the vendor.

Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Routed In Shield.

  • No contractual safety net: with no terms, privacy policy or data processing agreement published, a compliance platform is being handed sensitive security findings under no stated commitment
  • The contact details on the main site are unchanged template defaults, including an email address on a domain with no mail records and a fictional +1 (555) telephone number, while the company is Latvian
  • A public subdomain serves the application populated with openly fictitious demonstration records, including an invented company name, registration number and Riga address; none of it describes the real vendor
  • The subscription figure visible in the site's code is an error fallback rather than an advertised price, so quoting it back as the tariff would be a mistake
  • Every unknown web address returns the home page with a success code, so a link that appears to work is no proof that the page exists
  • Automated compliance can breed false confidence: generated policies and dashboards evidence a posture, they do not by themselves make an organisation secure or certified
  • No certification of the vendor is named anywhere, so the frameworks on display should be read as what the product helps you achieve, not as credentials Routed In holds
Setup

Setup & Integrations

Technical difficulty

Moderate to high, and hard to size from outside. The platform expects connections to AWS, Azure or GCP accounts and a Graylog SIEM feed, which calls for real infrastructure skills rather than an administrator alone. The application includes an onboarding step and the vendor sells consultation time, so the deployment is evidently assisted, but no public documentation describes the path. That a custom integration is priced at 3,500 EUR of setup is a fair indication that connecting Shield to an existing estate is not a trivial exercise.

Deployment

Web app

Integrations

Cloud Custodian Graylog AWS Azure GCP

Supported languages

EnglishLatvian
Company

Behind Routed In Shield

Company name
Routed In
Founded
INFORMATION_NOT_FOUND
Country of origin
🇱🇻 Latvia
Headquarters
Saules 9, Jelgava, 3002, Latvia
UBO
INFORMATION_NOT_FOUND
UBO country
🇱🇻 Latvia
Domain registrar country
🇺🇸 United States
Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What does Routed In Shield actually cover?
Five frameworks from a single platform: NIS2, ISO 27001, ISO 42001, GDPR and SOC 2. Around them the product adds automated risk assessment, AI-generated policies, DNS and email intelligence, cloud security monitoring and real-time dashboards.
Who is behind the product?
Routed In, a cybersecurity and DevOps firm established in Latvia. The address published on the company's own landing page is Saules 9, Jelgava, 3002, Latvia. The company presents itself as drawing on Latvian academic expertise.
How much does it cost?
Six add-on services are priced publicly in euros, from 225 EUR per vCISO hour to 8,000 EUR for a penetration test. The subscription tiers are not publicly verifiable: the plan grid is shown only if the vendor's backend enables it, so you should ask for a written quotation.
Is there a free plan or a free trial?
Neither is mentioned anywhere on the site. No trial period, no free tier and no refund policy is published.
Does Shield offer an API?
No. There is no product API and no public technical documentation. The site does mention API integrations, but that is a development service Routed In performs for clients, not an interface exposed by Shield.
Which third-party tools does it integrate with?
Cloud Custodian is embedded for cloud compliance checks across AWS, Azure and GCP, and Graylog is named as the SIEM feeding the dashboards.
Where is customer data hosted?
This is not published. There is no security page, no trust centre and no privacy policy, so no hosting jurisdiction is stated. The AWS, Azure and GCP references describe the customer environments being monitored, not where the vendor stores data.
Is the product GDPR compliant?
The site never makes that claim for itself. GDPR appears as one of the frameworks Shield helps customers satisfy. Routed In publishes no privacy policy of its own, names no data protection officer and offers no data processing agreement.
What languages does the interface support?
English and Latvian. English is served by default.
How do you get in touch?
Through the contact form on the home page or the consultation request on the Shield page. The main site publishes no email address; a general address, info@routedin.com, appears on the company's separate landing page.
Conclusion

Should you pick Routed In Shield?

Routed In Shield makes an unusually broad promise for a company this small: five compliance frameworks in one platform, including ISO 42001 for AI management systems, wrapped in automated risk assessment, AI-generated policies and continuous cloud monitoring. The integrations it names — Cloud Custodian and Graylog — are concrete and checkable, the European footing is genuine, and publishing firm euro prices for penetration tests, gap assessments and vCISO hours is a welcome break from a market that quotes everything privately.

The difficulty is how little of this can be verified from outside. The site is a JavaScript application that serves almost no readable markup, loads its content from a hosted backend and answers every unknown address with its home page. It publishes no terms of service, no privacy policy and no cookie policy: all three footer links lead nowhere. It names no certification of its own and no customer, although it has sections built for both. Its contact block still carries template defaults that were never replaced, including an undeliverable address and a fictional telephone number, and a public subdomain serves the application filled with openly fictitious demonstration records. The one subscription figure visible in the code is an error fallback, not an advertised price.

None of that makes the offer unserious — the underlying application is real and substantial, and small vendors often run ahead of their paperwork. It does mean the buying process has to supply what the website does not. Shield is worth a conversation for a European company that needs NIS2 or ISO 27001 without building a compliance team, provided the contract, the price and the data commitments are all obtained in writing first.