Telemetry and data-flow review status
Controlled-preview engineering inventory; not an approved telemetry policy or blanket data-location promise.
Controlled-preview documentation
Shielda is not generally available. Source code, fixtures, tests, version labels, plans, and historical checklists do not establish live availability, compatibility, compliance, or contract terms.
REVIEW STATUS — NOT AN EFFECTIVE POLICY. Exact collection, purpose, storage, provider, retention, deletion, and customer-control behavior must be verified for the evaluated deployment.
Current boundary
Optional Google Analytics on the public website is off by default and loads only after a visitor allows it. Shielda's site-event layer uses allowlisted page and interaction fields and does not send request-form contents, names, email addresses, URL queries, hashes, or referrers. A browser Do Not Track or Global Privacy Control signal keeps it off. Google can still process network, browser, and device data when enabled.
Browser replay, browser error/performance telemetry, and browser CSP reporting are not enabled through this preference. Necessary operational and security records may still be required for an approved product workflow.
Candidate product data can include account and organization information, connected-service metadata, agent identity and health, service inventory, scanner output, findings, evidence, model usage records, audit events, and support communications. This list is not a declaration that every category is collected.
No blanket local-only claim
Collection may occur in a customer-approved environment, while selected inventory, findings, evidence, operational records, or model input may be transmitted to a control plane or external provider. The actual flow depends on the connector, model policy, provider, workflow, and deployment.
Evidence required for an approved policy
For each live event or record, document its fields, trigger, purpose, legal and operational owner, tenant scope, destination, provider, region, access path, security controls, retention, deletion, export, and configuration default. Validate the stated behavior against the exact deployed release.
Do not place passwords, API keys, source code, exploit payloads, customer data, or other sensitive material in a general website form or initial email. See the privacy status for the current public boundary.