Terms of Service
Rules for using ShieldRun
These Terms govern use of ShieldRun. They are separate from the Privacy Policy, which explains data processing, and the Trust & Security page, which provides non-contractual product transparency.
Acceptance of these Terms
By creating a ShieldRun account, selecting the agreement checkbox, or using the service, you agree to these Terms. If you use ShieldRun for an organization, you represent that you have authority to accept these Terms for that organization. If you do not agree, do not create an account or initiate a scan.
ShieldRun records the Terms version you accept and the time of acceptance. If an account has not accepted the required version, ShieldRun requires the customer to review and explicitly accept it before using authenticated service features. The customer can still view the Terms and Privacy Policy, sign out, or request account deletion without accepting.
Service provider and contact
The service provider is ShieldRun, an independent business established in and operated from the European Union. In these Terms, “ShieldRun,” “we,” “us,” and “our” refer to that service provider.
Legal contact: support@shieldrun.net.
Eligibility and accounts
You must be at least 18 years old to create or purchase a ShieldRun account independently and must be legally able to enter into these Terms. ShieldRun is available to individual consumers and to businesses and other organizations. If you act for an organization, you confirm that you have authority to bind it. Do not register on behalf of another person without authority.
These Terms apply to both business customers and consumers. Nothing in them excludes or restricts mandatory consumer protection, statutory remedies, data-protection rights, or any other right that cannot lawfully be waived under EU or other applicable law.
Registration requires an email address, a qualifying password, acceptance of the current Terms, and email verification before protected domain and billing actions. Information you provide must be accurate and kept current. You are responsible for protecting credentials, controlling access to your account, and promptly reporting suspected compromise. Do not share session, verification, reset, or domain-proof tokens.
What ShieldRun provides
ShieldRun provides point-in-time automated external security assessment for internet-facing websites and related infrastructure. Depending on scan type and plan, it can inspect observable HTTP, TLS, DNS, email-security, port, service, web-configuration, public asset, and vulnerability-intelligence signals; produce findings and an external configuration score; generate HTML/PDF reports; compare scans; and schedule daily, weekly, or monthly Full Scans.
Quick Scan is a temporary, limited assessment that makes bounded requests to publicly accessible HTTP, TLS and DNS services. It does not authenticate, exploit vulnerabilities, brute-force credentials or perform port scanning. Full Scan is a broader automated external security assessment and may include bounded network, service and web-security probes against an authorized, verified target. When explicitly configured by an authorized customer and supported by the customer's plan, a Full Scan may use customer-provided authentication credentials or custom request headers against that verified target. ShieldRun provides automated security assessment and does not provide a human-led penetration-testing or red-team engagement unless expressly offered under a separate agreement. Additional assets found through public-source discovery are not actively probed unless the additional asset is separately verified and authorized.
Acceptable use
Use ShieldRun only for lawful defensive assessment of systems you are authorized to test. Respect plan limits, account and domain roles, target availability, third-party rights, and reasonable instructions intended to protect the service. Findings and reports may be used to understand and remediate the authorized systems covered by the assessment.
Prohibited activity
You must not use, attempt to use, or help others use ShieldRun to:
- scan or test any system without authorization;
- scan beyond the targets, methods, credentials, environments, time windows, or other scope covered by that authorization;
- circumvent domain verification, account roles, plan limits, rate limits, or other access controls;
- intentionally disrupt, overload, damage, or degrade a system;
- conduct denial-of-service, load, or stress testing;
- exploit a discovered or suspected vulnerability;
- obtain or maintain unauthorized access;
- provide credentials, authentication material, accounts, tokens, headers, or secrets that you are not entitled to use;
- deliberately cause an authenticated scan to access data, resources, users, or environments outside your authorization;
- use Custom Request Headers to facilitate unauthorized access or impersonation;
- steal, extract, intercept, or solicit credentials, secrets, personal data, or private information;
- create, deliver, host, or distribute malware or harmful code;
- conduct unlawful surveillance, attacks, fraud, harassment, or abuse;
- use findings, reports, or discovered assets to attack a third party;
- use ShieldRun with the intent to compromise, damage, or interfere with a third party; or
- violate applicable law, contract, or another person's rights.
ShieldRun may refuse or limit a scan, or restrict, suspend, or terminate an account, when it reasonably suspects unauthorized activity, abuse, a threat to a target or the service, or a material breach of these Terms.
Assessment limitations
ShieldRun provides a point-in-time automated external security assessment. Findings represent conditions observable during the assessment, and security conditions can change immediately after a scan. No automated scanner can identify every vulnerability, misconfiguration, asset, dependency, or risk. A clean report or absence of a finding does not establish absence of vulnerabilities, and a high or 100 score is not a guarantee of security.
Results may contain false positives, false negatives, incomplete evidence, or unavailable assessments. Individual controls and coverage may be labelled NOT_ASSESSED, PARTIAL, UNKNOWN, INDETERMINATE, NOT_APPLICABLE, or with another capability or availability limitation. Coverage can also depend on DNS, certificate-transparency, vulnerability-intelligence, network, target, and third-party service availability.
Infrastructure, software, vulnerabilities, credentials, DNS, certificates, dependencies, configurations, and attacker techniques can change after a scan. Implementing ShieldRun recommendations or fixing every reported finding does not guarantee future security or prevent later compromise, hacking, business interruption, a cyberattack, or a data breach.
Findings, scores and guidance
Findings, scores, priorities, reports, and remediation guidance are provided for informational and security-assistance purposes from ShieldRun's automated external checks. Guidance is generic and must be reviewed for your own technology, availability requirements, change controls, and risk tolerance. You are responsible for deciding whether scanning or remediation actions are appropriate for your environment before initiating or applying them, for testing and safely applying changes, and for the continuing security, backups, monitoring, patching, and operation of your systems.
ShieldRun reports are not penetration-test certifications, regulatory or compliance certifications, warranties, insurance assessments, guarantees of security, or guarantees that the customer will not suffer a cyberattack or data breach. You must not represent them as such.
No professional advice
Findings, remediation guidance, scores and reports provide technical security information. They are not legal, regulatory, insurance or compliance advice. Customers requiring formal penetration testing, certification, regulatory assessment or professional security assurance should obtain an appropriate qualified professional service.
Availability and service changes
ShieldRun may be unavailable because of maintenance, service updates, failures, target behavior, provider outages, security response, or other operational conditions. No uptime SLA, guaranteed scan completion time, support response time, or uninterrupted service is currently offered. ShieldRun may change, add, restrict, or retire features and limits to maintain, secure and improve the service. ShieldRun will give reasonable notice of material customer-facing changes where practicable and where applicable law or an existing paid agreement requires it. These provisions do not remove ShieldRun's responsibility to provide a service actually purchased or any mandatory remedy for failure to do so.
Plans and usage limits
- Free — €0: 1 verified domain and 3 manual Full Scans each calendar month.
- Beginner — €29/month or €290/year: 5 verified domains and 25 manual Full Scans each calendar month.
- Pro — €59/month or €590/year: 10 verified domains, 50 manual Full Scans each calendar month, daily/weekly/monthly scheduling, change detection, and up to 90 days of security history and historical reports.
- Business — €119/month or €1,190/year: 10 verified domains, 150 manual Full Scans each calendar month, up to 365 days of security history, all existing Pro capabilities, and eligible Business security and integration features made available in the product.
A yearly subscription changes billing frequency, not entitlement limits. Manual Full Scan quotas reset at the start of each UTC calendar month even when billing is yearly. Scheduled scans are separate from the manual quota. The current pricing page is the source for the displayed catalog and current plan availability. Paid plan descriptions are informational unless and until checkout is offered with applicable purchase terms.
Subscriptions and billing
ShieldRun may offer paid subscriptions through Lemon Squeezy hosted checkout. Before redirecting to checkout, ShieldRun shows the selected plan, monthly or yearly billing interval, recurring price, renewal basis, cancellation information, and links to these Terms and the Privacy Policy. The hosted checkout must show the final order total and applicable taxes before payment is completed.
Monthly subscriptions are billed monthly and yearly subscriptions are billed yearly. They renew automatically for the selected interval until cancelled. Unless the purchase information or mandatory law provides otherwise, a confirmed cancellation stops future renewal and paid access remains available through the applicable paid period. Expired, ended, unpaid, payment-failed, or refunded subscriptions do not provide paid access. A paused subscription may continue to provide paid access while the payment provider reports it as paused.
Checkout, payment information, subscription management, and the customer portal are handled through Lemon Squeezy hosted services. Lemon Squeezy acts as Merchant of Record and authorized reseller for the transaction: the customer purchases through Lemon Squeezy, while the ShieldRun operator is the Supplier that provides and supports the ShieldRun service. Lemon Squeezy's Buyer Terms and checkout disclosures also apply to the purchase.
As Merchant of Record, Lemon Squeezy handles payment collection, applicable sales tax and VAT, payment-card compliance, refund processing, and chargebacks. ShieldRun receives the verified subscription status needed to grant or remove service access and remains responsible for delivering and supporting the ShieldRun service as Supplier.
ShieldRun may change plan features or prices prospectively. Changes do not alter an already paid period. Any change affecting a future recurring charge will be communicated and applied only as permitted by the purchase terms and applicable law. A customer who does not want to renew at a changed price may cancel before the change applies.
Refunds and consumer rights
ShieldRun sets the customer-facing refund policy for its service, subject to mandatory law and Lemon Squeezy's Merchant-of-Record terms. Lemon Squeezy processes refunds and generally handles chargebacks, and it reserves the rights described in its current terms to issue refunds in appropriate cases. Unless the purchase information or mandatory law states otherwise, cancelling a recurring subscription prevents future renewal but does not by itself create a refund for the current paid period. Refund and withdrawal requests may be sent to the legal contact above or submitted through the Lemon Squeezy process shown at purchase.
Nothing in these Terms waives a refund, cancellation, withdrawal, repair, replacement, price reduction, termination, conformity or other consumer right that cannot lawfully be waived. Any provider terms presented during a future purchase may also apply to payment support, refunds, or chargebacks, without restricting mandatory rights against the responsible trader or service provider.
ShieldRun intellectual property
ShieldRun and its licensors retain rights in the service, software, interface, branding, report templates, documentation, scoring methodology, and remediation library. Subject to these Terms, ShieldRun grants you a limited, non-exclusive, non-transferable right to use the service for your own authorized defensive-security purposes. You may not copy, resell, sublicense, or reverse engineer protected service components except where applicable law does not allow that restriction.
Customer materials and reports
You retain any rights you have in domain information and other material you submit. You represent that you have the rights and authorization needed to submit it and permit ShieldRun to process it to provide, secure, and support the service. You are responsible for the accuracy and lawfulness of submitted targets and account membership decisions.
You may download and use reports about your authorized targets and share them internally or with employees, contractors, auditors, insurers and professional advisers who have a legitimate need to receive them. Reports can reveal sensitive security weaknesses; you are responsible for storing and sharing them appropriately and for respecting third-party rights. Report output does not transfer ownership of ShieldRun's software, scanner technology, templates, scoring methodology, trademarks or documentation.
Privacy
The Privacy Policy explains how ShieldRun collects, uses, stores, shares, and deletes personal information and customer scan data. It is incorporated into these Terms by reference for those data-processing descriptions. It is not a substitute for these service-use rules. As described there, ShieldRun does not sell customers' personal data. Necessary processors, service providers and legally required disclosures remain possible under the Privacy Policy.
Suspension and termination
ShieldRun may restrict, suspend, or terminate access when reasonably needed to investigate or respond to suspected unauthorized scanning, abuse, security threats, legal violations, non-payment for an applicable paid subscription, or material breach of these Terms. Where appropriate and legally permitted, ShieldRun will provide notice and a reasonable opportunity to address the issue when practicable. Immediate action may be needed to protect targets, customers, third parties, or the service.
Account deletion
You may request account deletion from Settings. ShieldRun revokes sessions and disables scheduled monitoring, then provides a seven-day recovery period. Once permanent deletion starts, recovery is unavailable and eligible account, exclusive domain, scan, finding, report, and billing records are removed as described in the Privacy Policy. Shared resources belonging to other users and narrowly anonymized audit events may remain. Deletion is not immediate and does not require erasure of transaction, accounting, legal-claim or other records that applicable law requires or permits ShieldRun or a provider to retain.
Before permanent account deletion, ShieldRun must cancel any linked recurring subscription through the billing provider. If cancellation cannot be confirmed, permanent deletion remains blocked rather than silently deleting the local billing link. You should cancel through the authenticated customer portal before requesting deletion, or contact ShieldRun support for assistance.
Third-party services
ShieldRun relies on or communicates with services including Resend for transactional email, Lemon Squeezy for hosted billing services when those services are available, and public security-data sources such as crt.sh, Cert Spotter, NVD, and CISA. Scans also interact with customer-authorized targets, DNS resolvers, and network operators. Third-party availability, content, and terms are outside ShieldRun's control. Use of a third-party purchase or portal surface may be subject to that provider's terms and privacy notice.
Warranty disclaimer
To the maximum extent permitted by applicable law, ShieldRun is provided “as is” and “as available.” ShieldRun does not promise uninterrupted operation, error-free reports, complete discovery, a particular score, prevention of a security incident, or that results will be suitable or sufficient for a particular compliance, certification, regulatory, or assurance requirement. Any statutory warranty or consumer protection that cannot lawfully be excluded remains unaffected. This disclaimer does not remove ShieldRun's responsibility to supply the service actually purchased in conformity with these Terms and mandatory law.
Business-customer indemnity
Business customers only
This section applies only when the customer uses ShieldRun in the course of a trade, business, craft, or profession. It does not apply to consumers.
To the extent permitted by applicable law, a business customer will indemnify ShieldRun against third-party claims and reasonable documented costs to the extent caused by that customer's unauthorized or out-of-scope scanning or testing; unauthorized submission or use of credentials or other access material; violation of applicable law, third-party rights, or hosting, network, or service-provider terms that the customer was responsible for observing; unlawful use of reports or findings; or breach of the authorization representations in these Terms.
This provision does not require a customer to indemnify ShieldRun for loss to the extent caused by ShieldRun's own breach or conduct for which responsibility cannot lawfully be transferred. It does not override mandatory consumer protections or any right or remedy that applicable law does not permit the parties to exclude or restrict.
Limitation of liability
To the maximum extent permitted by applicable law, ShieldRun is responsible for loss caused by its breach of these Terms or other legally actionable conduct only to the extent provided by applicable law. ShieldRun does not seek to exclude or limit liability that cannot lawfully be excluded or limited, including mandatory liability and remedies available to consumers.
A scan or action taken in response to a recommendation does not guarantee prevention of hacking, a data breach, business interruption or another security incident. That limitation does not excuse ShieldRun from providing the service actually purchased.
To the extent permitted by applicable law, ShieldRun is not liable for indirect, incidental, special, consequential, or punitive loss, or for lost profits, revenue, business, anticipated savings, data, goodwill, or business interruption arising from use of the service, inability to use the service, or a customer's unauthorized or out-of-scope use. This exclusion does not apply to liability or remedies that cannot lawfully be excluded or limited, and it does not make authorized scanning risk-free.
To the extent permitted by applicable law, ShieldRun is not responsible for loss to the extent caused by a customer's unauthorized or out-of-scope use; failure to maintain appropriate backups, recovery arrangements, change controls, or maintenance windows; or decision to rely solely on ShieldRun results for a security, compliance, or remediation decision contrary to these Terms. This allocation applies only to the customer-caused portion of the loss and does not exclude or limit liability where doing so is prohibited by applicable law.
These Terms do not set a separate contractual monetary cap; ShieldRun's liability is determined under applicable law.
Governing law and disputes
These Terms are governed by applicable EU and member-state law. This does not deprive a consumer of mandatory protections available under the law of the consumer's country of residence. Business-customer disputes are subject to the competent courts determined by applicable law unless the parties validly agree otherwise. Consumers may bring or defend proceedings in any court available under mandatory EU or other applicable consumer-jurisdiction rules.
Please first send a written complaint to support@shieldrun.net so the parties can try to resolve it. An eligible consumer may also use a consumer dispute-resolution process available under applicable EU or other mandatory law. Court remedies remain available as provided by law.
Changes to these Terms
ShieldRun may update these Terms as the service and applicable requirements change. The dates above will be updated. ShieldRun will communicate material changes through an appropriate account or service notice before they take effect where required by applicable law. A material change requiring renewed agreement will use a new Terms version and require explicit acceptance before authenticated service use continues. ShieldRun will not silently record acceptance of future Terms. If you do not accept a required new version, you may sign out, read the legal documents, and use the available account-deletion process.
Contact
Questions, complaints and formal notices about these Terms can be sent to support@shieldrun.net.
