The FindIP Threat Network
Shield is free. In return, every free Shield site contributes pseudonymized, infrastructure-level sightings to the shared corpus that makes Shield's and FindIP's risk intelligence better for everyone — including you. This page is the complete and exact description of that contribution. Contract version: free-preview-2026-08-09.
The deal in one paragraph
Networks, not people
When a visitor triggers an event on your site, Shield records which network the visitor came from and what kind of action they attempted — an IP address, its network flags, and a coarse event category. It does not record who the visitor is, what they typed, or what page they were on. Your site itself appears in the corpus only as an irreversible pseudonym. That's the entire contribution.
Exactly what a sighting contains
The complete field list
| Contributor | HMAC pseudonym of your site (not your domain, name, or account); pseudonym key version |
| Network | Visitor IP; ASN; country code; VPN / proxy / Tor / relay / hosting / datacenter / malicious / scanner / public-DNS flags; whether intelligence was available |
| Time | Server receipt time (never the browser's clock) |
| Behavior | Coarse event class (telemetry or action), event name (e.g. login_attempt), auto-detected flag, coarse confidence bucket |
| Bookkeeping | Random sighting ID, source event ID (duplicate suppression), schema/pipeline versions |
What a sighting never contains
Enforced in code, not just policy
The sighting record is assembled from a fixed field list, and the ingest API independently strips anything sensitive server-side — even if a client bypasses the SDK.
How pseudonymization works
Irreversible by design
Your site appears in the Threat Network only as an HMAC-SHA256 value computed with a secret key stored outside every database. Nobody analyzing the corpus — including FindIP analysts — can turn a pseudonym back into a customer, domain, or account. The pseudonym exists solely so that "how many distinct sites saw this IP" can be counted without knowing which sites they were.
What FindIP will never build from this data
Structural commitments
Collection by privacy mode
Contribution is identical in every mode
What the SDK sends to your own dashboard depends on your privacy mode (see Data Collection). The Threat Network contribution does not: it derives from the server-observed connection (IP + network flags + coarse event class), not from anything collected in the browser. Page URLs, session/visitor IDs, user-agents, form metadata, and customer context never reach the Threat Network in any mode.
Retention
Fixed windows
| Raw site events | Your dashboard — per-site setting, default 30 days |
| Site aggregates | Your dashboard — per-site setting, default 365 days |
| Raw network sightings | Threat Network — 90 days |
| Aggregated network reputation | Long-term (no site pseudonyms tied to raw traffic) |
Deleting a Shield site deletes its events, sessions, and aggregates through the normal retention job. Sightings cannot be traced back to a site and age out within 90 days regardless.
Your responsibilities as a site owner
You direct this processing
By creating a Shield site you confirm that you have the authority to install the SDK on that site, that you direct the processing described on this page as part of your site's data collection, and that you alone are responsible for its lawfulness for your site — including all visitor notices, privacy-policy disclosures, and consents your jurisdictions require. Shield's consent API (FindIP.consent()) and strict mode are tools available to you; selecting and operating a compliant configuration is your responsibility, not FindIP's. See the Free Preview terms for the full allocation of responsibility.
Requests, security & changes
Contact and versioning
| Deletion / export | Email [email protected] with your site ID |
| Security reports | [email protected] |
| Subprocessors | Cloudflare (CDN, network ingress, edge caching); everything else runs on FindIP's own infrastructure |
| Incidents | Confirmed incidents affecting your data are reported to your account email without undue delay |
Material changes to this contract bump the version string. Existing sites keep operating under the version they accepted (recorded at site creation); a re-acceptance prompt appears when a new version applies.