# The FindIP Threat Network

Contract version: **free-preview-2026-08-09**

Shield is free. In return, every free Shield site contributes **pseudonymized,
infrastructure-level sightings** to the FindIP Threat Network — the shared corpus that makes
Shield's and FindIP's risk intelligence better for everyone, including you. This page is the
complete and exact description of that contribution. If a future version of Shield ever needs
more than what is listed here, this contract's version changes and existing sites are asked
again.

## The deal in one paragraph

When a visitor triggers an event on your site, Shield records **which network the visitor came
from and what kind of action they attempted** — an IP address, its network flags, and a coarse
event category. It does **not** record who the visitor is, what they typed, or what page they
were on. Your site itself appears in the corpus only as an irreversible pseudonym. That's the
entire contribution.

## Exactly what a sighting contains

| Group | Fields |
|---|---|
| Contributor | HMAC pseudonym of your site (not your domain, name, or account), pseudonym key version |
| Network | visitor IP address; ASN; country code; VPN / proxy / Tor / relay / hosting / datacenter / malicious / scanner / public-DNS flags; whether intelligence was available |
| Time | server receipt time (never the browser's clock) |
| Behavior | coarse event class (`telemetry` or `action`), event name (e.g. `login_attempt`), auto-detected flag, coarse confidence bucket |
| Bookkeeping | random sighting ID, source event ID (duplicate suppression), schema/pipeline versions |

## What a sighting never contains

- Session IDs or visitor IDs
- Your users' account identifiers or hashes
- The visitor's user-agent string
- Page URLs, paths, titles, referrers, or UTM parameters
- Form field names or values — Shield never reads input values anywhere
- Cookies, local storage, DOM content, keystrokes, or pointer movements
- Your domain, site name, or FindIP account identity

These exclusions are enforced in code and by tests, not by policy alone: the sighting record is
assembled from a fixed field list, and the ingest API independently strips anything sensitive
server-side even if a client bypasses the SDK.

## How pseudonymization works

Your site appears in the Threat Network only as an HMAC-SHA256 value computed with a secret key
that is stored outside every database. Nobody analyzing the corpus — including FindIP analysts —
can turn a pseudonym back into a customer, domain, or account. The pseudonym exists solely so
that "how many *distinct* sites saw this IP" can be counted without knowing which sites they
were.

## What FindIP will never build from this data

- **No cross-site profiles of people.** There is no visitor identifier in the corpus, so a
  person cannot be followed from one site to another. This is structural, not just policy.
- **No form data, ever.** Input values are never read by the SDK and are rejected server-side.
- **No sale of your site's traffic data.** Sightings power aggregated IP/network reputation —
  outputs are about *networks* (e.g. "this IP hit login forms on N distinct sites today"),
  never about your site or your users.

## Collection matrix by privacy mode

What the SDK sends to **your own Shield dashboard** depends on the privacy mode you choose
(see [Privacy Modes](https://www.findip.net/docs/shield/privacy-modes.md) and [Data Collection](https://www.findip.net/docs/shield/data-collection.md)):

| Data | strict | balanced | advanced | Reaches Threat Network? |
|---|---|---|---|---|
| Event name + timestamp | ✓ | ✓ | ✓ | coarse class + name only |
| Page URL / path / referrer / UTM | ✓ | ✓ | ✓ | **never** |
| Session + visitor IDs (first-party) | ✓ | ✓ | ✓ | **never** |
| User-agent, language, timezone | ✓ | ✓ | ✓ | **never** |
| Screen/viewport, platform, touch | — | ✓ | ✓ | **never** |
| Form metadata (never values) | — | ✓ | ✓ | **never** |
| Allowlisted customer context | — | ✓ | ✓ | **never** |
| Visitor IP + network flags (server-side) | ✓ | ✓ | ✓ | ✓ (the core of a sighting) |

The Threat Network contribution is **identical in every privacy mode** — it derives from the
server-observed connection, not from anything the SDK collects in the browser.

## Retention

| Data | Where | Retention |
|---|---|---|
| Raw site events | your Shield dashboard | per-site setting, default 30 days |
| Site aggregates | your Shield dashboard | per-site setting, default 365 days |
| Raw network sightings | Threat Network corpus | 90 days |
| Aggregated network reputation | Threat Network corpus | long-term (contains no site pseudonyms tied to raw traffic) |

Deleting a Shield site deletes its events, sessions, and aggregates through the normal retention
job. Sightings are not deleted with the site — they cannot be traced back to it — but they age
out within 90 days regardless.

## Your responsibilities as a site owner

By creating a Shield site you confirm that you have the authority to install the SDK on that
site, that you direct the processing described on this page as part of your site's data
collection, and that **you alone are responsible for its lawfulness for your site** — including
all visitor notices, privacy-policy disclosures, and consents your jurisdictions require.
Shield's consent API (`FindIP.consent()`) and `strict` mode are tools available to you;
selecting and operating a compliant configuration is your responsibility, not FindIP's. See the
[Free Preview terms](https://www.findip.net/docs/shield/terms-free-preview.md) for the full allocation of responsibility.

## Data requests, deletion, export, and security

- **Deletion / export requests** for your site's event data: email
  [info@findip.net](mailto:info@findip.net) with your site ID.
- **Security issues**: report to [info@findip.net](mailto:info@findip.net).
- **Subprocessors**: Cloudflare (CDN, network ingress, edge caching). Everything else runs on
  FindIP's own infrastructure.
- **Incidents**: confirmed incidents affecting your data are reported to your account email
  without undue delay.

## Changes to this contract

Material changes bump the version string at the top. Existing sites keep operating under the
version they accepted (recorded at site creation); a re-acceptance prompt appears in the
dashboard when a new version applies to them.

---

Canonical page: https://www.findip.net/docs/shield/threat-network · Markdown: https://www.findip.net/docs/shield/threat-network.md · All Shield docs in one file: https://www.findip.net/llms-full.txt
