Security

Found something? Tell us.

Security software has to hold itself to a higher standard than what it protects. If you find a weakness in anything EndShields runs, we want to hear about it.

Last updated 11 September 2026

Report a vulnerability

Email security@endshields.com. It helps if you include:

  • What you found and where: the URL, or the app version and platform.
  • Steps to reproduce it.
  • What an attacker could do with it.

Please don't access or change other people's data, disrupt the service, or publish the details before we've had a chance to fix it. We'll confirm we've received your report and keep you updated as we work on it.

In scope

  • endshields.com and its subdomains, including the customer portal.
  • The EndShields desktop app for Windows and macOS.
  • The EndShields monitoring agent.

Where the product stands

EndShields is pre-launch, and we'd rather you hear the rough edges from us. The desktop app installers aren't code-signed yet, so Windows and macOS will warn you when you open one. Signing them is part of our hardening before public release.

What the app sends off your device, and who can see it, is set out in what leaves your device.

Machine-readable contact

Our contact details are also published at /.well-known/security.txt, following RFC 9116.