SireShielda codesire company
Questions & answers

Targeted spyware, in plain English

Pegasus is the name people know, but it is one product in an industry that keeps producing new ones. These answers are about that whole class of threat — no jargon, no scare tactics, and no promises we can't keep. If your question isn't here, ask our Director directly at privacy@codesire.net.

What is SireShield?

SireShield is a security service for people who are likely to be deliberately targeted — senior officials, politicians, judges, lawyers, journalists and human-rights defenders. It watches your phone continuously for signs of mercenary spyware — the commercial surveillance tools sold to governments — blocks connections to known attacker infrastructure, flags settings that make you easier to attack, and puts a real analyst on the other end of the line when something looks wrong. It is a brand of CodeSire Private Limited and is available by application only.

Who is SireShield for?

People whose phones hold consequence. In practice that means government officials and diplomats, elected politicians, prosecutors and judges, NGO and human-rights staff, lawyers, and journalists — the groups that keep turning up in confirmed spyware cases. If your work makes someone want to read your messages before you send them, you are the kind of person this is built for. If you just want general phone hygiene, ordinary security software is a better fit and we will tell you so.

What is mercenary spyware?

Mercenary spyware is surveillance software built and sold commercially — usually to governments — to take over a specific person's phone. It is an industry, not a single product: Pegasus is the name most people know, but Predator, Graphite, Candiru and others do the same job, and new ones appear as old ones are exposed and shut down. Unlike ordinary malware, it is not sprayed at millions of people hoping someone clicks. It is aimed at you, by name or by phone number. Once installed it can read your messages, listen through the microphone, see the camera, and track your location. We wrote a plain-English explainer here: how this class of spyware works.

How does spyware get onto a phone if I never click anything?

This is the part most people find hardest to believe. The serious tools use zero-click attacks: a message, an image or a call arrives, your phone processes it automatically the way it processes everything, and a flaw in that processing is enough to let the attacker in. You never tap a link. There is no dodgy app to avoid installing. Nothing appears on screen. That is exactly why "I'm careful online" is not a defence against this class of attack — and why continuous checking matters more than caution.

Can SireShield stop this kind of spyware?

No — not with certainty, and we will not pretend otherwise. Nobody can guarantee that: not us, not any company, not any product. A determined attacker with a brand-new, undisclosed flaw in your phone's operating system can get in, and anyone who tells you they can stop that is selling you something. What we honestly do: we block what is already known (malicious servers, phishing links, known spyware infrastructure), we shrink the ways in by flagging missing updates and risky settings, and we detect and warn on the rest — fast, with evidence you can act on. Catching an infection in days instead of years is the difference this service actually makes.

How is this different from antivirus or a VPN?

Antivirus is built for mass-market malware — bad apps, scam files, things that infect millions of people. It is not designed for a tool that exists in a handful of copies and is pointed at one person. A VPN hides which network you are on; it does nothing about spyware already living on your device. SireShield is built for the targeted case: it looks for the specific fingerprints and behaviours of mercenary spyware, correlates several different kinds of evidence, and comes with human analysts rather than only a scan button.

How do I know if my phone is already hacked?

Honestly? Usually you can't tell by looking. Cheap stalkerware often leaves clues — a hot phone, fast battery drain, odd data use, apps you don't recognise. Professional mercenary spyware is built specifically to leave none of that. Most confirmed victims found out because a researcher or Apple told them, not because they noticed something. We wrote a practical walkthrough of the checks worth doing: is my phone hacked or infected with spyware?

What about spyware that hasn't been discovered yet?

This is the honest hard edge of the whole field, so we would rather address it than hide it. Matching known fingerprints catches what the world has already documented — and by definition it cannot catch what nobody has seen yet. Two things narrow that gap. First, speed: when researchers publish indicators for a newly discovered tool, our coverage updates automatically and your device is re-checked against them — so an infection from three months ago can surface the week the world learns about it. Second, and this one we describe as a direction we are actively building toward rather than a finished capability, we are drawing on a combination of research-based open-source intelligence and commercial tooling, and extending that further threat intelligence alongside our open sources and to flag anomalous, spyware-like behaviour before a matching public indicator exists. The window is never zero. It is much shorter than doing nothing, and it closes a little further every month.

Which phones does SireShield work on?

Both iPhone and Android. The two are not identical, and we are open about why: Android lets a security app see more of what is happening on the device, so protection there is deeper and more continuous. Apple deliberately stops any app from inspecting other installed apps, so on iPhone we cannot scan your installed apps — we say so inside the app itself, and we lean on the checks iOS does allow. We would rather explain that limit than quietly imply the two are the same.

Does SireShield read my messages, photos or contacts?

No. We look at security signals — your device's patch level, its settings and integrity, and connection metadata such as which servers your phone is talking to. We are not interested in the content of your messages, your photos, your contacts or your browsing, and reading them would defeat the whole point of the service. Wherever a check can run on your phone instead of on our servers, it does. When you check whether a password has leaked, the password never leaves your device — only a short, irreversible fragment of a hash is ever sent.

What does SireShield actually tell me?

Three plain verdicts, never "safe" or "infected": Clear, Watch, or Compromise-likely. Every alert comes with a confidence level and a timeline of the evidence behind it, so you can see why we are saying it rather than being handed a colour. Security is probabilistic, and a product that pretends to certainty is misleading you.

What happens if it finds something?

You are not left alone with a scary screen. An analyst reviews the evidence with you, helps you preserve it properly (which matters if the case ever becomes legal or public), and walks you through containment: securing your accounts and sessions, rotating credentials, deciding whether the device can be trusted again or should be replaced, and what to tell the people you communicate with. Where appropriate we will also point you to independent researchers such as Amnesty's Security Lab or The Citizen Lab.

Why do I have to apply? Can't I just download it?

Because the people we protect are targets, and an open download queue is an open invitation for the wrong people to study the product. Every applicant is reviewed by a SireShield analyst, and we speak to you before activating anything. It is slower on purpose. If you are approved, you get a private link to register for the app.

How much does SireShield cost?

There are three ways to work with us. Protect is continuous protection on your own device. Managed adds a named analyst who already knows your case, and availability for it is limited, deliberately. A one-time investigation is a single forensic examination of a single handset, for someone who needs an answer now and nothing after it — no subscription, nothing recurring. See what each one includes. We discuss the price with you during the application call rather than posting a checkout page, because what you need depends on your risk and your platform. If you are a journalist or a human-rights defender working without institutional funding, say so in your application — we keep room for cases like that.

Why should I trust a security company with my phone?

You shouldn't, on faith. Trusting a security product is itself a security decision. Our answer is not "trust us" but "here is why you don't have to": we collect as little as possible so there is little to compromise or compel, sensitive checks run on your own device, we are bound by India's Digital Personal Data Protection Act including its breach-notification duties, and we name a real, reachable person who is accountable. We also publish exactly what we have not yet done — we have no third-party audit or ISO certification yet, and we say so. The full account is on our Trust & Transparency page.

What is Quantum Vault?

Encryption for your most sensitive files that is designed to survive quantum computers. The threat is called "harvest now, decrypt later": an adversary copies your encrypted data today, stores it, and waits for a machine capable of breaking today's encryption. For most people that is theoretical. For someone whose documents will still be sensitive in ten or twenty years, it is a real planning problem.

What can I do right now, before I even apply?

Four things, all free. Install every operating-system update the day it arrives — most confirmed spyware infections used a flaw that already had a patch. Turn on Lockdown Mode if you use an iPhone and you are genuinely at risk; it closes off many of the paths these attacks use. Restart your phone regularly, since some implants do not survive a reboot. And turn on two-factor authentication everywhere, preferably with a hardware key or passkey rather than SMS. None of that makes you invulnerable, but it removes a great deal of the easy road in.

Still not sure whether you need this?

That's the right question to be asking. Tell us what you do and what worries you — a SireShield analyst reads every application personally.

See if you qualify →

Read next: What this spyware actually does to a phone · Is my phone hacked? · Trust & Transparency