Privacy Policy
Your data at ShieldRun
This policy explains, in plain language, what ShieldRun saves when you create an account or scan an internet-facing system, why we use it, when it may be shared, and how deletion works.
Who controls your information
ShieldRun is the controller for personal information it processes for its own account, security, billing, support, service operations, and abuse-prevention purposes. The service provider and controller for those purposes is ShieldRun, an independent business established in and operated from the European Union.
When a business customer instructs ShieldRun to assess an authorized system and the scan processes personal data relating to that customer's users, employees, or other individuals, ShieldRun may act as a processor on behalf of that customer, depending on the circumstances. The customer remains responsible for establishing its instructions, lawful basis, notices, and permissions where it acts as controller.
Privacy questions and requests can be sent to support@shieldrun.net.
What customer data ShieldRun saves
The following is a practical inventory of customer information saved by the service. Some scan information may be personal data when it identifies a person, account, device, or small organization.
Account and profile
Email address, optional display name, a password hash (not the password), account role and plan, verification and account status, Terms acceptance, and account-deletion information.
Authentication and sessions
Protected representations of session, security, email-verification, password-reset, and guest-access tokens; session expiry, use, and revocation times; and privacy-preserving security signals derived from the connecting IP address and browser information when available.
Domains and permissions
Submitted domain names and URLs, ownership attestations, account access roles, domain-verification details, and scan schedule preferences such as cadence, local time, and timezone.
Scans, findings and reports
Scan targets and public IP addresses; authorization, status, errors, and timestamps; relevant HTTP, TLS, DNS, port, service, technology, and asset evidence; findings, recommendations, scores, changes, security history, and generated reports.
Authenticated Scanning and custom request headers
Profile names and settings, and encrypted authentication credentials or custom request-header values supplied for authorized scans. Secret values are write-only and are not displayed again after configuration.
Security, audit and abuse prevention
Limited records of security-relevant actions, outcomes, affected resources, and errors. Privacy-preserving client identifiers may be used for security auditing and rate limiting. ShieldRun also keeps limited records about scan processing, status, retries, and errors.
Billing and subscription
When paid billing services are available, ShieldRun may store Lemon Squeezy customer and subscription identifiers, the selected plan and billing interval, subscription status, renewal or end dates, and limited transaction and billing event information needed to administer paid access.
Messages to us
If you contact support, security, or privacy support, we and the systems used to receive the message process the contact details and content you choose to send.
We do not sell customer data
ShieldRun does not sell personal data to anyone. Customer scan data, findings, security history, and reports are not used for third-party advertising.
Scan data and evidence
ShieldRun examines publicly reachable website, HTTP, TLS, DNS, port, service and related security configuration data for a domain or URL submitted by a customer. Full scans can also use public certificate-transparency sources and public vulnerability information to build an external asset and risk view.
ShieldRun saves normalized evidence needed to explain findings and compare security history. This can include safe response headers, redirect URLs, public IP addresses, certificate and DNS details, observable cookie names and security attributes, and detected service or technology markers. It does not persist observed cookie values or complete HTTP response bodies. Small, bounded response bodies may be read in memory for specific checks, such as confirming a security.txt file or recognizing an exposed-file signature, but the body itself is not saved.
Most scans assess externally observable behavior without target credentials. When an eligible customer explicitly requests an authenticated scan, ShieldRun may use the configured credentials for that requested assessment of the verified target. ShieldRun does not use this feature for credential brute forcing or exploitation. Customers should submit only systems and access material they are authorized to use for the assessment.
Credentials and custom request headers
Authenticated Scanning credentials
Customers may optionally provide credentials for an explicitly requested authenticated scan. ShieldRun processes them to provide that feature and stores the configured credential values in encrypted form rather than as plaintext. Credential values are write-only: ShieldRun indicates that credentials are configured but does not display their values again.
ShieldRun does not intentionally include those credential values in findings, report snapshots, HTML/PDF/CSV exports, Developer API responses, Webhook payloads, email content, audit metadata, or routine service logs. Removing the authentication profile removes its stored credential value from the active service. Backup and operational retention are addressed below and may not disappear at the same moment as active-service data.
Custom Request Headers
Customers may optionally configure custom request-header values for authorized scans where their plan supports the feature. ShieldRun stores those values in encrypted form and does not display them again after configuration. ShieldRun does not intentionally include the values in findings, reports, exports, Developer API responses, Webhooks, emails, audit metadata, or routine service logs.
Removing a configured header removes its active encrypted value from ShieldRun's active service. Disabling a profile or header prevents its configured use but may preserve the encrypted value so the customer can re-enable it where the service permits.
Why we use information
- create, verify, authenticate, secure and recover accounts;
- confirm domain authority and provide requested scans, monitoring, findings, history and reports;
- apply plan limits and administer subscriptions;
- deliver transactional email, respond to support and privacy requests, and communicate about the service;
- process scans, store requested results, diagnose failures, and maintain service reliability;
- prevent abuse, investigate security events, enforce service rules, and protect customers, ShieldRun and others; and
- meet applicable legal obligations and lawful requests.
Legal bases
Where data-protection law requires a legal basis, ShieldRun relies on performance of a contract or steps requested before entering one to provide accounts, scans and billing; legitimate interests in securing, operating and supporting the service and preventing abuse; compliance with legal obligations; and consent where a specific optional use requires it. The basis depends on the information and purpose. Legitimate interests are used only where they are not overridden by applicable individual rights and interests.
Payments and billing
When paid billing services are available, Lemon Squeezy provides hosted checkout and customer-portal services and processes payment information under its own privacy terms. ShieldRun receives and stores subscription and billing-status information needed to administer paid access. ShieldRun does not store full payment-card numbers, card security codes, or raw payment-card details.
International transfers
ShieldRun is operated from the European Union, but service providers may process information in other countries. ShieldRun handles international transfers as required by applicable data-protection law. Contact support@shieldrun.net for information about processing locations and safeguards relevant to a particular service.
How long information is kept
ShieldRun keeps information for the period needed to provide and secure the service, apply the lifecycle below, resolve disputes, and meet applicable obligations. Current retention periods and lifecycle rules include:
- account sessions are usable for up to 12 hours; email verification links for 24 hours; password-reset links for 1 hour; domain-verification challenges for 24 hours; and guest sessions and limited public scans for 24 hours;
- temporary scan-processing records are generally retained for up to one hour after successful completion and up to seven days after failure, subject to operational limits;
- account, domain, membership, full-scan, finding, history, report and subscription records otherwise remain in the active service while needed for the account and are removed through the account-deletion lifecycle; expired information may become unusable before it is removed from active records;
- encrypted Authenticated Scanning credentials and Custom Request Header values remain in the active service while their configurations are retained. Removing a profile or header removes its active configuration; account or exclusive-domain deletion also removes linked configurations. Historical backups and independently retained operational records follow their separate retention lifecycles;
- general application/security logs, unaffected audit records, database backups, email-provider records and provider-side billing records have separate operational or provider retention. Exact windows depend on the service, provider and any applicable legal duty; contact support@shieldrun.net for current retention information;
Account deletion and recovery
An authenticated customer can request deletion from Settings → Privacy & Data. ShieldRun immediately revokes active sessions, invalidates outstanding reset access, and disables scheduled monitoring. The account then enters a seven-day grace period. The customer can recover it while it remains pending deletion, including when deletion is blocked until shared-domain ownership is resolved. Recovery does not automatically re-enable monitoring schedules.
Once permanent deletion starts, normal sign-in and recovery are disabled. ShieldRun removes the account, sessions and account tokens; billing information held by ShieldRun; memberships; exclusive domains and their verification, schedules, authentication profiles and custom request-header configurations; personal or exclusive scans and their normalized evidence, findings, scores, history and reports; and related scan-processing and report files. A scan owned by another customer is preserved, but its link to the deleted requester is removed. Shared resources belonging to other users are preserved.
Most linked audit records are deleted. Only narrowly selected failed-login and ownership-transfer events may remain after user, domain, scan, network and metadata fields are removed. ShieldRun may retain a minimal non-identifying record that permanent deletion was completed.
Deletion removes active-service data but does not guarantee immediate erasure from historical backups, provider systems, or independently retained operational logs. Backups are kept outside the active service, and recorded deletions must be reapplied before restored data can return to normal use. Provider systems, transaction or accounting records, and other information may also be retained where applicable law requires or permits retention.
Your privacy rights
Depending on where you live, you may have rights to ask whether ShieldRun processes your personal information, request access or a copy, correct inaccurate information, request deletion or restriction, object to certain processing, or withdraw consent where consent is used. These rights can have legal exceptions, and ShieldRun may need to verify your identity before responding. Privacy requests should be sent to support@shieldrun.net.
You may complain to the competent EU data-protection authority for your place of residence, place of work, or the location of an alleged infringement.
How we protect information
ShieldRun uses measures appropriate to the service and the risks involved, including Argon2id password hashing; protected session and verification values; secure random tokens; HttpOnly and SameSite cookies; origin and CSRF checks; account and domain authorization; request and scan limits; public-address validation; limited security audit data; signed webhook verification; and safeguards for deletion and restoration. Configured Authenticated Scanning credentials and Custom Request Header values are encrypted at rest and are not displayed again after configuration. No system can guarantee absolute security.
Children and minimum age
ShieldRun is a technical security service intended for people authorized to assess internet-facing systems. A person must be at least 18 years old to create or purchase a ShieldRun account independently. ShieldRun does not provide a parental-consent account mechanism. If you believe a person under 18 has created an account, contact support@shieldrun.net so it can be reviewed.
Changes and contact
ShieldRun may update this policy when the service or applicable requirements change. Material changes will be communicated by an appropriate service notice where required, and the effective and last-updated dates above will be revised.
For questions, requests, or concerns about privacy, contact support@shieldrun.net.
