ShieldRunScan. Detect. Protect.

Trust & Security

Security visibility with deliberate boundaries.

ShieldRun helps teams understand publicly observable security signals while keeping scan scope constrained, evidence focused, and unnecessary target content out of persistent storage.

Bounded by designPassive where discovery expandsEvidence, not content

Scanning boundaries

A defined path from authorization to insight.

We keep the collection path understandable: authorized targets receive bounded checks, and the resulting security evidence is normalized into findings and reports.

01Authorized target
02Bounded checks
03Security evidence
04Findings
05Report & history
Discovered assetsPassive observation only

Additional discovered assets remain passive and are not actively probed unless separately authorized.

Service safeguards

Useful signals, less unnecessary data.

Purpose-bound scanning

Limited public scans require an authorization attestation. Domain ownership verification is required before Full Scan monitoring is enabled.

Passive discovery

Additional discovered assets remain passive and are not actively probed unless separately authorized.

No exploitation

ShieldRun does not attempt to exploit vulnerabilities, submit forms, or perform brute-force testing. Authenticated Scanning runs only when an authorized customer explicitly configures and requests it.

Minimized collection

The scanner is designed to normalize relevant security evidence instead of retaining unnecessary target content.

Sensitive values protected

Configured authentication credentials and custom request-header values are encrypted and kept out of findings, reports, exports, Webhooks, emails, and routine service logs. The scanner does not persist observed cookie values or complete HTTP response bodies.

Protected accounts

Session cookies are HttpOnly and SameSite=Strict. State-changing requests are protected by origin and CSRF validation; passwords are hashed with Argon2id.

Authorization matters

Ownership and permission are part of the boundary.

Limited public scans require a user authorization attestation. Domain ownership verification is required before Full Scan monitoring is enabled.

Security contact

Found a security issue in ShieldRun? Contact us.

Please email our support team with the details so we can review the issue.

Contact security support