Loading...
Loading...
Transparency First. Last Updated: July 16, 2026
This Privacy Policy explains how Orygn LLC collects, uses, shares, and protects information when you use the WebShield Audit platform (the "Service"). We operate on a principle of "Minimal Viable Data": we collect only what is necessary to run the scanner, prevent abuse, and keep the Service reliable. WebShield requires no account and no signup.
When you scan a target, our engine reads that site's public HTTP responses, including its headers, any Set-Cookie headers (so we can check cookie security flags), and page content, in order to score them. Sensitive values (cookie values, authorization headers, and any secrets our exposure checks surface) are redacted before any scan result is cached or shared. We do not retain a scanned site's session cookie values.
To run the scan and deliver the Service, data is transmitted to third-party providers in the following categories (all currently based in the United States):
A scan also causes our server to request the target site itself and the third-party resources that site references. This is inherent to how scanning works. We may add or change providers within these categories; a current list of providers is available on request at security@orygn.tech.
WebShield sets no tracking cookies of its own. We use a minimal set of functional storage:
You may request deletion of cached data related to domains you own by contacting us.
We implement commercially reasonable technical and organizational measures to protect data from unauthorized access, loss, or misuse.
Breach Notification: In the event of a data breach affecting personal data we hold, we will investigate promptly and notify affected users and any applicable regulators as required by law.
We do not sell, trade, or rent any user data to third parties. We are not a data broker. Even as a "free" tool, you are the user, not the product.
Depending on where you live, you may have the right to access, correct, delete, or port your personal data, and to object to or restrict its processing. California residents have the right to know, delete, and opt out of the sale or sharing of personal information; we do not sell or share personal information. We process IP addresses under our legitimate interest in preventing abuse and securing the Service.
To exercise any of these rights, or to request deletion of data, contact us at security@orygn.tech. We will respond within the timeframe required by applicable law.
The Service is not directed to children under 16 (or the minimum age required in your jurisdiction), and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.
Orygn LLC is based in the United States and processes data there. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the US where our servers and central database are located. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for these transfers. By using the Service, you understand that your information will be processed in the US.
If you have questions about this Privacy Policy or our data practices, please contact:
security@orygn.tech