Shieldome ("we", "us", "our") is a web security scanning service. Our platform performs passive vulnerability assessments and performance analysis of websites you are authorized to test. We do not perform active exploitation or penetration testing.
For users in the EU/EEA, we process your data on the following legal bases:
We use strictly necessary cookies (session, language preference) that do not require consent. We may also use optional analytics cookies — you can manage these via the cookie banner shown on your first visit.
Scan results are retained for 12 months from the scan date. Account data is retained for the duration of your account plus 30 days after deletion. You can request deletion at any time.
Under GDPR (EU users) and applicable data protection laws, you have the right to:
To exercise these rights, open a support ticket or email us at the address in your account settings.
All data is transmitted over HTTPS/TLS. Passwords are hashed using bcrypt. We use CSRF protection, secure cookie flags (HttpOnly, SameSite), and role-based access controls. Two-factor authentication (TOTP) is available for all accounts.
We are based in Serbia and may process data on servers within the EU/EEA. If data is transferred outside the EEA, we use Standard Contractual Clauses to ensure adequate protection.
We will notify registered users of material changes via email at least 14 days before they take effect. Continued use after the effective date constitutes acceptance.
For privacy questions or to exercise your rights, open a support ticket while logged in, or contact us at the email address on your account profile.