Shield · Threat Network

The FindIP Threat Network

Shield is free. In return, every free Shield site contributes pseudonymized, infrastructure-level sightings to the shared corpus that makes Shield's and FindIP's risk intelligence better for everyone — including you. This page is the complete and exact description of that contribution. Contract version: free-preview-2026-08-09.

The deal in one paragraph

Networks, not people

When a visitor triggers an event on your site, Shield records which network the visitor came from and what kind of action they attempted — an IP address, its network flags, and a coarse event category. It does not record who the visitor is, what they typed, or what page they were on. Your site itself appears in the corpus only as an irreversible pseudonym. That's the entire contribution.

Exactly what a sighting contains

The complete field list

ContributorHMAC pseudonym of your site (not your domain, name, or account); pseudonym key version
NetworkVisitor IP; ASN; country code; VPN / proxy / Tor / relay / hosting / datacenter / malicious / scanner / public-DNS flags; whether intelligence was available
TimeServer receipt time (never the browser's clock)
BehaviorCoarse event class (telemetry or action), event name (e.g. login_attempt), auto-detected flag, coarse confidence bucket
BookkeepingRandom sighting ID, source event ID (duplicate suppression), schema/pipeline versions

What a sighting never contains

Enforced in code, not just policy

PeopleNo session or visitor IDs, no account identifiers or hashes, no user-agent strings.
NavigationNo page URLs, paths, titles, referrers, or UTM parameters.
ContentNo form field names or values (input values are never read anywhere), no cookies, DOM content, keystrokes, or pointer movements.
YouNo domain, site name, or FindIP account identity.

The sighting record is assembled from a fixed field list, and the ingest API independently strips anything sensitive server-side — even if a client bypasses the SDK.

How pseudonymization works

Irreversible by design

Your site appears in the Threat Network only as an HMAC-SHA256 value computed with a secret key stored outside every database. Nobody analyzing the corpus — including FindIP analysts — can turn a pseudonym back into a customer, domain, or account. The pseudonym exists solely so that "how many distinct sites saw this IP" can be counted without knowing which sites they were.

What FindIP will never build from this data

Structural commitments

No cross-site profiles of peopleThere is no visitor identifier in the corpus, so a person cannot be followed from one site to another.
No form data, everInput values are never read by the SDK and are rejected server-side.
No sale of your site's traffic dataOutputs are about networks (e.g. "this IP hit login forms on N distinct sites today"), never about your site or your users.

Collection by privacy mode

Contribution is identical in every mode

What the SDK sends to your own dashboard depends on your privacy mode (see Data Collection). The Threat Network contribution does not: it derives from the server-observed connection (IP + network flags + coarse event class), not from anything collected in the browser. Page URLs, session/visitor IDs, user-agents, form metadata, and customer context never reach the Threat Network in any mode.

Retention

Fixed windows

Raw site eventsYour dashboard — per-site setting, default 30 days
Site aggregatesYour dashboard — per-site setting, default 365 days
Raw network sightingsThreat Network — 90 days
Aggregated network reputationLong-term (no site pseudonyms tied to raw traffic)

Deleting a Shield site deletes its events, sessions, and aggregates through the normal retention job. Sightings cannot be traced back to a site and age out within 90 days regardless.

Your responsibilities as a site owner

You direct this processing

By creating a Shield site you confirm that you have the authority to install the SDK on that site, that you direct the processing described on this page as part of your site's data collection, and that you alone are responsible for its lawfulness for your site — including all visitor notices, privacy-policy disclosures, and consents your jurisdictions require. Shield's consent API (FindIP.consent()) and strict mode are tools available to you; selecting and operating a compliant configuration is your responsibility, not FindIP's. See the Free Preview terms for the full allocation of responsibility.

Requests, security & changes

Contact and versioning

Deletion / exportEmail [email protected] with your site ID
Security reports[email protected]
SubprocessorsCloudflare (CDN, network ingress, edge caching); everything else runs on FindIP's own infrastructure
IncidentsConfirmed incidents affecting your data are reported to your account email without undue delay

Material changes to this contract bump the version string. Existing sites keep operating under the version they accepted (recorded at site creation); a re-acceptance prompt appears when a new version applies.