← Agent-Shield

Privacy Policy — Agent-Shield

Effective date: October 8, 2026

Operator: Startek Enterprise Solutions LLC, a Florida limited liability company (FL document L14000161560)

1. What this service does

Agent-Shield is a security scanner. You (or your AI agent, acting on your

instructions) submit text content; the service analyzes it for security

threats — prompt injection, leaked secrets, exposed personal data, and

SSRF-risk URLs — and returns a verdict (clean, suspicious, or

malicious) with per-class scores.

2. What we collect — and what we do not

We do NOT collect, log, or retain your submitted content. The text you

send for scanning exists in memory only for the duration of the scan and is

discarded when the response is returned.

What we do retain, per scan:

DataPurposeRetention
sha256 hash of the submitted contentAudit correlation (lets you match a verdict to your own logs without us holding the text)90 days
Aggregate match counts (e.g. { "class": "ssn", "match_count": 2 })Service metrics and abuse detection90 days
Verdict and per-class scoresService metrics90 days
Timestamp, API key label (not the key)Rate limiting, abuse prevention, billing90 days

We never store the matched text itself — findings reference pattern classes

(ssn, aws_key, ssrf), never the sensitive values that triggered them.

3. Account and billing data

Signup requires only a label you choose — no email address, no name. We

store your API key record and label in Cloudflare KV for authentication,

rate limiting, and billing. These records are kept while your account is

active and deleted when you close it.

Pro billing ($19/month) is processed by Stripe Checkout and activates with

the semantic classifier launch — no charges occur before then. Your card details

go directly to Stripe — we never see or store them. We receive only the

subscription status and identifiers needed to upgrade or downgrade your key.

Stripe's handling of payment data is governed by Stripe's own privacy

policy: https://stripe.com/privacy

4. DNS lookups

To assess SSRF risk, URLs found in your content are resolved via DNS. Only

the hostname (never query strings or fragments, which may contain secrets)

is looked up. Resolved IP classifications (e.g. "cloud_metadata", "public")

may be retained as part of the finding; the full URL is stored only as a

sha256 hash.

5. What we do not do

6. Data location

The service runs on Cloudflare's edge network. Scan processing happens in

the region closest to the request; aggregate records are stored in

Cloudflare KV.

7. Subprocessors

SubprocessorRoleData handled
Cloudflare, Inc.Hosting, edge compute, KV storageAPI key records; scan hashes and aggregate counts
Stripe, Inc.Payment processingSubscription status and identifiers; card data goes to Stripe directly

We do not share scan content with any subprocessor — there is no content

to share.

8. Your rights

Because we do not retain your content, there is nothing to export or delete

beyond the aggregate records above. To request deletion of aggregate records

associated with your API key label, or to close your account and delete your

key record, contact the address below.

9. Changes

Material changes to this policy will be posted at this URL at least 14 days

before taking effect.

10. Contact

Startek Enterprise Solutions LLC

Email: startek@startekenterprises.com