Purpose-bound scanning
Limited public scans require an authorization attestation. Domain ownership verification is required before Full Scan monitoring is enabled.
Trust & Security
ShieldRun helps teams understand publicly observable security signals while keeping scan scope constrained, evidence focused, and unnecessary target content out of persistent storage.
Scanning boundaries
We keep the collection path understandable: authorized targets receive bounded checks, and the resulting security evidence is normalized into findings and reports.
Additional discovered assets remain passive and are not actively probed unless separately authorized.
Service safeguards
Limited public scans require an authorization attestation. Domain ownership verification is required before Full Scan monitoring is enabled.
Additional discovered assets remain passive and are not actively probed unless separately authorized.
ShieldRun does not attempt to exploit vulnerabilities, submit forms, or perform brute-force testing. Authenticated Scanning runs only when an authorized customer explicitly configures and requests it.
The scanner is designed to normalize relevant security evidence instead of retaining unnecessary target content.
Configured authentication credentials and custom request-header values are encrypted and kept out of findings, reports, exports, Webhooks, emails, and routine service logs. The scanner does not persist observed cookie values or complete HTTP response bodies.
Session cookies are HttpOnly and SameSite=Strict. State-changing requests are protected by origin and CSRF validation; passwords are hashed with Argon2id.
Authorization matters
Limited public scans require a user authorization attestation. Domain ownership verification is required before Full Scan monitoring is enabled.
Security contact
Please email our support team with the details so we can review the issue.