Terms of Service
Last updated: September 20, 2026
These Terms of Service ("Terms") govern your use of SecureShield ("the Service"). By creating an account or using the Service, you agree to these Terms.
1. What the Service does
SecureShield monitors websites you own or are authorized to manage. For each verified domain, we check uptime, SSL certificate status, HTTP security headers, and whether a small set of commonly sensitive files are publicly exposed. You must verify ownership or control of a domain — via a DNS record or file check — before we begin monitoring it.
Separately, if you explicitly enable it for a domain and point that domain's DNS at SecureShield, the Service can also act as a reverse proxy with basic firewall (WAF) rules, filtering requests that match common attack patterns (such as SQL injection or cross-site scripting attempts) before forwarding traffic to your real origin server. This proxy feature is opt-in per domain and is described further in Section 5.
The Service may also send you alerts by email or to a webhook URL you configure, and can expose account data via an API key you generate.
2. Your account
You're responsible for keeping your login credentials, API key, and any webhook URL secure, and for all activity under your account. Notify us if you believe your account, API key, or webhook has been compromised.
3. Domain verification and ownership
You may only add domains you own or are authorized to manage on behalf of their owner. Verification (via DNS TXT record or file upload) is how we confirm this, and monitoring or proxying does not begin until verification succeeds. Adding a domain you're not authorized to manage is a violation of these Terms, independent of whether verification technically succeeds.
4. Acceptable use
You agree not to:
- Add, monitor, or proxy a domain you don't own or don't have authorization to manage
- Use the Service, including the reverse proxy feature, to route traffic for a site engaged in illegal activity, or to obscure the true origin or ownership of such a site
- Use the Service to attack, disrupt, or gain unauthorized access to any system
- Attempt to reverse engineer, scrape, or overload the Service
5. Reverse proxy / WAF feature — specific terms
The proxy/WAF feature is provided as a first layer of filtering, not a comprehensive security solution. Its rule set is intentionally simple and is not equivalent to a mature, actively-maintained WAF product. Enabling it means traffic to your domain is routed through our infrastructure before reaching your origin server; you are responsible for ensuring your origin server configuration (host, port, protocol) is correct, since a misconfiguration on your end can cause your site to become unreachable while the feature is enabled. You can disable this feature or update your origin configuration at any time from your dashboard.
6. Plans and billing
Free and paid plans offer different limits on the number of websites you can monitor or proxy, described on our pricing page. Paid plan subscriptions (Starter, Business and Agency) are billed monthly in advance and are processed by our payment partner, Polar (polar.sh), which handles payment collection and, where applicable, sales tax/VAT for your purchase. SecureShield does not see or store your card details. Refunds are handled under our separate Refund Policy.
7. Service availability
We aim for reliable monitoring and proxying but don't guarantee uninterrupted service. Scheduled maintenance, upstream provider issues, or unforeseen technical issues may cause temporary downtime in monitoring, alerting, or the proxy feature.
8. Termination
You may stop using the Service and delete your account at any time; this also disables any active proxy configuration for your domains. We may suspend or terminate accounts that violate these Terms, including unauthorized domain monitoring or misuse of the proxy feature.
9. Disclaimer
The Service, including its monitoring checks and proxy/WAF filtering, is provided "as is" without warranties of any kind. A passing security grade, a clean file scan, or the WAF not blocking a given request does not mean your site is free of vulnerabilities. SecureShield is not liable for losses resulting from undetected threats, false positives or false negatives, missed alerts, or service or proxy interruptions.
10. Changes to these Terms
We may update these Terms from time to time as the Service changes. Continued use of the Service after changes means you accept the updated Terms.
11. Contact
Questions about these Terms can be sent through the contact options available in your dashboard.