ShieldRunScan. Detect. Protect.

Privacy Policy

Your data at ShieldRun

This policy explains, in plain language, what ShieldRun saves when you create an account or scan an internet-facing system, why we use it, when it may be shared, and how deletion works.

Effective
30 August 2026
Last updated
30 August 2026

Who controls your information

ShieldRun is the controller for personal information it processes for its own account, security, billing, support, service operations, and abuse-prevention purposes. The service provider and controller for those purposes is ShieldRun, an independent business established in and operated from the European Union.

When a business customer instructs ShieldRun to assess an authorized system and the scan processes personal data relating to that customer's users, employees, or other individuals, ShieldRun may act as a processor on behalf of that customer, depending on the circumstances. The customer remains responsible for establishing its instructions, lawful basis, notices, and permissions where it acts as controller.

Privacy questions and requests can be sent to support@shieldrun.net.

What customer data ShieldRun saves

The following is a practical inventory of customer information saved by the service. Some scan information may be personal data when it identifies a person, account, device, or small organization.

Account and profile

Email address, optional display name, a password hash (not the password), account role and plan, verification and account status, Terms acceptance, and account-deletion information.

Authentication and sessions

Protected representations of session, security, email-verification, password-reset, and guest-access tokens; session expiry, use, and revocation times; and privacy-preserving security signals derived from the connecting IP address and browser information when available.

Domains and permissions

Submitted domain names and URLs, ownership attestations, account access roles, domain-verification details, and scan schedule preferences such as cadence, local time, and timezone.

Scans, findings and reports

Scan targets and public IP addresses; authorization, status, errors, and timestamps; relevant HTTP, TLS, DNS, port, service, technology, and asset evidence; findings, recommendations, scores, changes, security history, and generated reports.

Authenticated Scanning and custom request headers

Profile names and settings, and encrypted authentication credentials or custom request-header values supplied for authorized scans. Secret values are write-only and are not displayed again after configuration.

Security, audit and abuse prevention

Limited records of security-relevant actions, outcomes, affected resources, and errors. Privacy-preserving client identifiers may be used for security auditing and rate limiting. ShieldRun also keeps limited records about scan processing, status, retries, and errors.

Billing and subscription

When paid billing services are available, ShieldRun may store Lemon Squeezy customer and subscription identifiers, the selected plan and billing interval, subscription status, renewal or end dates, and limited transaction and billing event information needed to administer paid access.

Messages to us

If you contact support, security, or privacy support, we and the systems used to receive the message process the contact details and content you choose to send.

We do not sell customer data

ShieldRun does not sell personal data to anyone. Customer scan data, findings, security history, and reports are not used for third-party advertising.

Scan data and evidence

ShieldRun examines publicly reachable website, HTTP, TLS, DNS, port, service and related security configuration data for a domain or URL submitted by a customer. Full scans can also use public certificate-transparency sources and public vulnerability information to build an external asset and risk view.

ShieldRun saves normalized evidence needed to explain findings and compare security history. This can include safe response headers, redirect URLs, public IP addresses, certificate and DNS details, observable cookie names and security attributes, and detected service or technology markers. It does not persist observed cookie values or complete HTTP response bodies. Small, bounded response bodies may be read in memory for specific checks, such as confirming a security.txt file or recognizing an exposed-file signature, but the body itself is not saved.

Most scans assess externally observable behavior without target credentials. When an eligible customer explicitly requests an authenticated scan, ShieldRun may use the configured credentials for that requested assessment of the verified target. ShieldRun does not use this feature for credential brute forcing or exploitation. Customers should submit only systems and access material they are authorized to use for the assessment.

Credentials and custom request headers

Authenticated Scanning credentials

Customers may optionally provide credentials for an explicitly requested authenticated scan. ShieldRun processes them to provide that feature and stores the configured credential values in encrypted form rather than as plaintext. Credential values are write-only: ShieldRun indicates that credentials are configured but does not display their values again.

ShieldRun does not intentionally include those credential values in findings, report snapshots, HTML/PDF/CSV exports, Developer API responses, Webhook payloads, email content, audit metadata, or routine service logs. Removing the authentication profile removes its stored credential value from the active service. Backup and operational retention are addressed below and may not disappear at the same moment as active-service data.

Custom Request Headers

Customers may optionally configure custom request-header values for authorized scans where their plan supports the feature. ShieldRun stores those values in encrypted form and does not display them again after configuration. ShieldRun does not intentionally include the values in findings, reports, exports, Developer API responses, Webhooks, emails, audit metadata, or routine service logs.

Removing a configured header removes its active encrypted value from ShieldRun's active service. Disabling a profile or header prevents its configured use but may preserve the encrypted value so the customer can re-enable it where the service permits.

Cookies and browser storage

ShieldRun uses first-party cookies that are necessary for sign-in, session security, CSRF protection, account recovery, and limited guest scans. Session and guest cookies are HttpOnly; relevant cookies use SameSite=Strict and use Secure when the service is delivered over HTTPS. Authentication cookies expire or are cleared on logout and other security events according to the session lifecycle.

The selected light, dark, or system theme can be saved in your browser's local storage. ShieldRun does not use advertising cookies, third-party advertising trackers, product-analytics SDKs, or an error-monitoring SDK.

Why we use information

  • create, verify, authenticate, secure and recover accounts;
  • confirm domain authority and provide requested scans, monitoring, findings, history and reports;
  • apply plan limits and administer subscriptions;
  • deliver transactional email, respond to support and privacy requests, and communicate about the service;
  • process scans, store requested results, diagnose failures, and maintain service reliability;
  • prevent abuse, investigate security events, enforce service rules, and protect customers, ShieldRun and others; and
  • meet applicable legal obligations and lawful requests.

Sharing and service providers

ShieldRun discloses information only as needed to operate the service, process transactions, obtain requested external scan intelligence, protect the service, or comply with law. This is not a promise that data is never shared.

  • Resend: receives the destination email address and transactional message content for account verification, password resets, domain-access invitations, recipient verification, scheduled scan-completion notices, and enabled security-alert delivery. Security-alert messages include the monitored domain, scan completion time, severity/count summaries, concise change titles, remediation guidance, and an authenticated scan history link; raw scanner evidence is not sent.
  • Lemon Squeezy: when paid billing services are available, receives the account email, selected product or variant, an opaque checkout correlation value, and payment or subscription information needed to provide hosted checkout and the customer portal.
  • Infrastructure providers: providers that operate hosting, database, cache, queue, backup, or related infrastructure may process the information needed to operate and secure those services.
  • Public security-data services: full scans may send a submitted root domain to crt.sh or Cert Spotter for certificate-transparency discovery, and detected technology identifiers to public NVD services; ShieldRun may also retrieve CISA's public vulnerability catalogue.
  • Legal and safety disclosures: information may be disclosed when reasonably necessary to comply with a valid legal requirement, establish or defend legal claims, address fraud or abuse, or protect rights and safety.

Payments and billing

When paid billing services are available, Lemon Squeezy provides hosted checkout and customer-portal services and processes payment information under its own privacy terms. ShieldRun receives and stores subscription and billing-status information needed to administer paid access. ShieldRun does not store full payment-card numbers, card security codes, or raw payment-card details.

International transfers

ShieldRun is operated from the European Union, but service providers may process information in other countries. ShieldRun handles international transfers as required by applicable data-protection law. Contact support@shieldrun.net for information about processing locations and safeguards relevant to a particular service.

How long information is kept

ShieldRun keeps information for the period needed to provide and secure the service, apply the lifecycle below, resolve disputes, and meet applicable obligations. Current retention periods and lifecycle rules include:

  • account sessions are usable for up to 12 hours; email verification links for 24 hours; password-reset links for 1 hour; domain-verification challenges for 24 hours; and guest sessions and limited public scans for 24 hours;
  • temporary scan-processing records are generally retained for up to one hour after successful completion and up to seven days after failure, subject to operational limits;
  • account, domain, membership, full-scan, finding, history, report and subscription records otherwise remain in the active service while needed for the account and are removed through the account-deletion lifecycle; expired information may become unusable before it is removed from active records;
  • encrypted Authenticated Scanning credentials and Custom Request Header values remain in the active service while their configurations are retained. Removing a profile or header removes its active configuration; account or exclusive-domain deletion also removes linked configurations. Historical backups and independently retained operational records follow their separate retention lifecycles;
  • general application/security logs, unaffected audit records, database backups, email-provider records and provider-side billing records have separate operational or provider retention. Exact windows depend on the service, provider and any applicable legal duty; contact support@shieldrun.net for current retention information;

Account deletion and recovery

An authenticated customer can request deletion from Settings → Privacy & Data. ShieldRun immediately revokes active sessions, invalidates outstanding reset access, and disables scheduled monitoring. The account then enters a seven-day grace period. The customer can recover it while it remains pending deletion, including when deletion is blocked until shared-domain ownership is resolved. Recovery does not automatically re-enable monitoring schedules.

Once permanent deletion starts, normal sign-in and recovery are disabled. ShieldRun removes the account, sessions and account tokens; billing information held by ShieldRun; memberships; exclusive domains and their verification, schedules, authentication profiles and custom request-header configurations; personal or exclusive scans and their normalized evidence, findings, scores, history and reports; and related scan-processing and report files. A scan owned by another customer is preserved, but its link to the deleted requester is removed. Shared resources belonging to other users are preserved.

Most linked audit records are deleted. Only narrowly selected failed-login and ownership-transfer events may remain after user, domain, scan, network and metadata fields are removed. ShieldRun may retain a minimal non-identifying record that permanent deletion was completed.

Deletion removes active-service data but does not guarantee immediate erasure from historical backups, provider systems, or independently retained operational logs. Backups are kept outside the active service, and recorded deletions must be reapplied before restored data can return to normal use. Provider systems, transaction or accounting records, and other information may also be retained where applicable law requires or permits retention.

Your privacy rights

Depending on where you live, you may have rights to ask whether ShieldRun processes your personal information, request access or a copy, correct inaccurate information, request deletion or restriction, object to certain processing, or withdraw consent where consent is used. These rights can have legal exceptions, and ShieldRun may need to verify your identity before responding. Privacy requests should be sent to support@shieldrun.net.

You may complain to the competent EU data-protection authority for your place of residence, place of work, or the location of an alleged infringement.

How we protect information

ShieldRun uses measures appropriate to the service and the risks involved, including Argon2id password hashing; protected session and verification values; secure random tokens; HttpOnly and SameSite cookies; origin and CSRF checks; account and domain authorization; request and scan limits; public-address validation; limited security audit data; signed webhook verification; and safeguards for deletion and restoration. Configured Authenticated Scanning credentials and Custom Request Header values are encrypted at rest and are not displayed again after configuration. No system can guarantee absolute security.

Children and minimum age

ShieldRun is a technical security service intended for people authorized to assess internet-facing systems. A person must be at least 18 years old to create or purchase a ShieldRun account independently. ShieldRun does not provide a parental-consent account mechanism. If you believe a person under 18 has created an account, contact support@shieldrun.net so it can be reviewed.

Changes and contact

ShieldRun may update this policy when the service or applicable requirements change. Material changes will be communicated by an appropriate service notice where required, and the effective and last-updated dates above will be revised.

For questions, requests, or concerns about privacy, contact support@shieldrun.net.