ShieldSelf
Security & data

The IT sign-off, on one page.

HR champions, IT co-signs. This page is written for the person doing the co-signing — forward it as is. Every claim here is true at our current stage, including the “not yet” answers.

What it is, and how it runs.

Personal digital protection delivered in the browser. A scenario-led check, then short guided protection actions. Every simulation runs inside the product — spotting a phish in a mock inbox, never a trick sent to a real one.

  • A web application served over HTTPS. It runs entirely in the browser.
  • Nothing touches your endpoints. No agents, no plugins, no installers, no browser extensions, no MDM profiles.
  • No simulated phishing. So no spam-filter exemptions, no allowlisting, no mail-flow changes.
  • No integration to start. Admins invite people by work email, individually or by CSV.
  • Setup is an HR task, not an IT project. It takes about 10 minutes.

The data, all of it.

Per person, the employer-side record is three fields: name, work email, programme progress (sections completed, completion dates). That is the whole record.

We never ask for passwords. We don’t scan mailboxes, read messages, log keystrokes, or monitor devices. There is nothing on the device to do it with.

On the Complete tier, an employee can choose to add personal email addresses for breach monitoring. We check those addresses against known public breach data. We see addresses and breach matches — never passwords, never message content. Family members sign up themselves; the employer sees only that an invite was used.

Customer data is hosted in the UK/EEA. ShieldSelf is a UK company and UK GDPR applies to everything we do. The DPA names every subprocessor and the safeguard for any processing outside the UK/EEA.

The privacy wall is a security feature.

The employer sees programme progress and team aggregates. Personal and family breach data — monitored addresses, exposure history, family accounts — is segregated from the employer account and is never employer-visible. Not at any granularity, not at any admin role, not on request. This is architectural, not a settings toggle.

Two reasons this makes your company safer, not just your people happier:

  1. People only act on real exposure when the record is private. An employee who knows their breach history reaches HR will never add their real addresses. Then the monitoring protects nobody. The wall is what makes the protection real.
  2. Your admin console holds no sensitive exposure data. A compromised admin account at ShieldSelf leaks programme progress — not the breach histories of your workforce and their families. The wall shrinks the blast radius of the worst day.

Our stage, honestly.

ShieldSelf is an early-stage UK company. We hold no ISO 27001 or SOC 2 certificate yet, and we won’t imply otherwise. What we offer instead: a small and fully-described data footprint, a signed DPA, named subprocessors, a 72-hour breach-notification commitment, and direct access to the people who built it.

Straight answers — the twelve questions IT will ask.

QuestionStraight answer
What do we need to install?Nothing. It’s a website. No agents, plugins, extensions, or MDM profiles — on any device.
Does it touch our mail flow or spam filters?No. We send no simulated phishing, so we need no allowlisting, no filter exemptions, no gateway rules. The only email we send is the invite itself. Nothing on a schedule.
What personal data do you collect?Employer-side: name, work email, programme progress. That’s all. Complete tier adds employee-chosen monitored addresses — held behind the privacy wall, never employer-visible.
Where is data stored, and does UK GDPR apply?UK/EEA hosting. UK company, UK GDPR and the Data Protection Act 2018 apply. Any non-UK/EEA processing is named in the DPA with its safeguard.
Is data encrypted?Yes. TLS in transit, encryption at rest.
Is a DPA available?Yes, on request, before the pilot if you want it.
Who are your subprocessors?A deliberately short list: cloud hosting, transactional email, and breach-data lookup (Complete tier only). The DPA names each one. We give 30 days’ notice before adding any, and you can object.
What happens if you’re breached?We notify you without undue delay and within 72 hours of becoming aware, with what we know and what we’re doing. A contractual commitment in the DPA, not a policy page.
Have you been penetration tested? Any certifications?Not yet, and we won’t dress that up. An independent penetration test is planned before broad paid rollout, and pilot customers get the report when it lands. No ISO 27001 or SOC 2 certificate yet. We’ll answer your security questionnaire directly in the meantime.
Do you support SSO / SAML?Not yet. Sign-in is by work email today. SSO/SAML is on the roadmap and we won’t promise a date we can’t keep. If SSO is a hard requirement, tell us — real demand moves it up.
Which browsers do you support?Current versions of Chrome, Edge, Safari and Firefox, on desktop and mobile. No legacy-browser requirements.
What happens to our data when we leave?You export progress records first. We delete employer-side data within 30 days of contract end. Employees who activated personal or family protection keep those personal accounts if they choose — that data sat behind the privacy wall and was never part of the employer record.

What we need from IT.

Nothing.

  • No allowlisting.
  • No spam-filter or secure-email-gateway exemptions.
  • No mail rules, no MX changes.
  • No software deployment, no MDM push.
  • No firewall changes.
  • No integration work before the pilot.

Worth naming, because it’s unusual in this category. Phishing-simulation products need their fake emails to reach real inboxes, so their setup guides ask you to allowlist their sending domains in your spam filter and email gateway. That is a standing, deliberate exemption in your mail defences. It weakens the exact control it claims to test.

We teach phish-spotting inside the product — people judge six real-looking messages in a simulated inbox and see every tell revealed. No fake attack ever enters your mail flow. Your filters stay exactly as strong as they are today.

The DPA and terms, in plain English.

The signed documents govern. This is what they say, without the legalese:

  • For employer-side data, you are the controller and we are the processor. We process it on your instructions and for nothing else.
  • Personal and family accounts sit outside the employer contract. For those, we answer to the individual, not to you. That’s the privacy wall in contractual form.
  • What we hold for you: name, work email, programme progress. The DPA lists it exactly.
  • What we never do: sell data, run advertising, or use your people’s data to train AI models.
  • Subprocessors named in full. 30 days’ notice of any change, with a right to object.
  • Breach notification within 72 hours of us becoming aware. Contractual.
  • Exit: export your records, then we delete employer-side data within 30 days. No exit fees, no data hostage-taking.
  • Monthly billing available — no 3-year lock-in. The pilot is free: 20 people, 30 days, no card, and the same DPA terms apply to it.

Questions your IT lead wants answered by a person: security@shieldself.co.uk. We reply ourselves. The working drafts of our privacy notice and terms are also public.