Last updated: 2 August 2026
Nobody stops the weather, and nobody turns aside a determined, well-funded attacker holding a brand-new zero-day. Any company that tells you otherwise is selling you a promise it has no way to keep.
That is not an argument for standing out in the downpour. It is the argument for the umbrella — and for knowing exactly how wide it is, where it covers you, and where the rain still gets through. That is what the rest of this page is: the honest dimensions of the umbrella.
Because here is the thing about rain. Most people who are actually harmed are not brought down by the exotic, unprecedented storm. They are reached through a flaw their phone's maker had already fixed, an app they were persuaded to install, a password that turned up in somebody else's breach. Those are the drops we catch, in volume, every single day. And for the rest — the storm nobody saw coming — we set tripwires that fire on the effect of your data being taken rather than the name of whatever took it, so that even an attack we have never met leaves a mark we can see.
We will not tell you that you will stay dry. We will tell you, precisely and without flinching, how much of the rain we keep off you. We think you would rather have that than a promise.
SireShield is operated by CodeSire Private Limited, an Indian company (CIN U72502KA2017PTC098946) registered in Bengaluru, Karnataka. It is a continuous mercenary-spyware detection and bounded-protection service for people at elevated risk of targeted surveillance.
Mercenary spyware — Pegasus, Predator, Candiru, Paragon and their successors — is no longer the exclusive problem of spy agencies. It is bought and pointed at senior bureaucrats and highly placed officials, politicians, journalists, lawyers, and activists. Many of the people most likely to be targeted are the least likely to have personal device-security support of their own. SireShield exists to give those individuals continuous, honest, expert-backed protection that was previously available only to states and corporations — without pretending the problem is fully solvable, because it isn't.
The most important thing on this page is this section, because the fastest way to spot a dishonest security product is that it only tells you what it can do. Here is both.
We would rather you understand these limits and pair SireShield with good practice than believe you are invulnerable because you installed something.
We don't ask you to take our detection on faith. Here is what it is built on.
Our threat signals are drawn continuously from a combination of research-based open-source intelligence and commercial tooling. The open side is the work the security-research community publishes and relies on — including the mercenary-spyware indicator catalogue maintained by Amnesty International's Security Lab and the Mobile Verification Toolkit project, the stalkerware indicator set published by Echap, and curated feeds of malicious infrastructure. The commercial side covers ground the open sources cannot, most of all credential-exposure data. When new Pegasus, Predator or Paragon indicators are published, our coverage updates automatically. We are transparent that this is indicator-based detection, not magic.
Decoy tripwires. We place realistic but fake material on your device — a contact, a note, a set of credentials — each carrying a marker unique to your device. You will never use them, because they aren't real. But software that harvests a phone's contents takes everything indiscriminately, and the moment one of those markers is used anywhere in the world, we know your device is leaking. The tripwire doesn't ask what took the bait; it only reports that something did.
Behaviour, learned from your phone specifically. There is no universal definition of normal — your phone's normal is not anyone else's. So SireShield learns yours: how much data leaves while the screen is off, when the device wakes, what its rhythm looks like across the day. It builds that picture on the device itself and keeps adjusting as your habits shift. We deliberately do not let it raise an alarm on its own — life is irregular, and a product that cried wolf every time your routine changed would be worse than useless to someone under real stress. It corroborates. When the behavioural signal lines up with something else — a connection we blocked, an app holding access it shouldn't, a tripwire that fired — that combination raises a case, and a human analyst looks at it.
Most real infections, including ones attributed to expensive mercenary tools, get in through a flaw that had already been fixed by the phone's maker. The victim simply hadn't installed the update. SireShield checks your device against the catalogue of vulnerabilities known to be under active attack and tells you plainly when an update actually matters — and, just as importantly, says "we don't know" rather than showing you a green tick when it hasn't been able to make that comparison.
We are extending SireShield to draw on additional commercial threat-intelligence platforms alongside our current sources, widening what counts as "known" before an indicator reaches the public feeds. We describe this as a direction we are actively building toward — not a capability we claim to have finished — consistent with the roadmap below.
When you check a password, it is hashed on your device and only a short, irreversible fragment of that hash is ever sent — a technique called k-anonymity. Your password never leaves your phone, and we never see it. The network sensor compares DNS lookups against the threat list on your device and sends us only the fact that a known-malicious domain was blocked; your browsing history is never collected. Wherever a check can run on your device rather than on our servers, it does.
The threat list your device acts on is delivered as a signed artifact and verified on the device before it is trusted, so a tampered update can't quietly change what your app treats as dangerous.
SireShield is invitation-only and deliberately data-minimal. We collect what is needed to protect your device and support you, and we work hard not to collect more. The full detail is in our Privacy Policy; the short version:
You can delete your account yourself, from inside the app: Help → Your account → Delete my account and all my data. You don't have to ask us, you don't have to give a reason, and you don't have to wait for anyone here to action it.
Deletion takes effect 48 hours after you request it, and the app shows you the exact date and time before you confirm. That window exists for one reason: so a mistaken tap can be undone. It is not a cooling-off period, not a retention period, and not a chance for us to talk you round. During it we stop collecting from your devices immediately — from the moment you ask, not when the deletion runs — and your monitored-asset list is destroyed at once.
Only you can cancel it, and only from your own device. We deliberately do not email you a link. An email sitting in an inbox saying you are a SireShield subscriber is a document we would rather not create for someone in your position — and links in email are followed automatically by scanners and security filters, which would mean a machine could quietly undo a deletion you meant.
No one at SireShield can stop it. Not your analyst, not an administrator, not the Director. There is no such control in our systems. When the window closes, the erasure runs on your authority alone — our internal rule requiring two administrators to approve a destruction does not apply, because that rule exists to protect you from us, not to give us a say in your own deletion.
You can also end your subscription without deleting your record, or pause it — pausing stops all monitoring, deletes nothing, and you resume it yourself from the same screen. If you no longer have the device, use sireshield.io/delete or write to privacy@codesire.net.
When an erasure completes we destroy your application and the notes made about you, every device and its history, your reports, cases and written findings. What survives is a record that consent existed and an administrative audit trail, both with your identity replaced by a reference that cannot be traced back to you. We can give you written confirmation of exactly what was destroyed and what was kept.
Our answer is not "trust us" — it's "here's why you don't have to." We minimise what we collect so there is little to compromise or compel. Privacy-preserving techniques like on-device processing and k-anonymity mean the most sensitive checks never send us your raw data in the first place. We are bound by India's DPDP law, including its breach-notification duties, and we name a real, accountable person you can reach (below). And as we grow, we are committing to independent, third-party scrutiny — because in this field, verifiable beats trustworthy.
And one item on that list isn't a promise at all. You can destroy everything we hold about you from your own phone, on a 48-hour timer, and nobody who works here can reverse it — the capability does not exist in our software. Every other safeguard above asks you to believe something about our intentions. That one you can simply test.
If those safeguards aren't enough for your threat model, we would rather tell you that plainly than talk you into a false sense of security.
We think you deserve an honest picture of our maturity, not a wall of badges. So here is exactly where we stand today, and what we're committing to as we scale.
| Area | Status | Detail |
|---|---|---|
| Data-protection compliance | In place | Built to India's DPDP Act 2023 and DPDP Rules 2025 — itemised notice, consent records, data-principal rights, breach reporting, retention limits. |
| Privacy-by-design | In place | Data minimisation, on-device processing, and k-anonymity are core to how the product is built, not features added later. |
| Subscriber-controlled deletion | In place | Subscribers delete their own account from the app, on a 48-hour timer they can cancel and nobody else can. No employee, analyst or administrator can hold, postpone or reverse a deletion a subscriber has requested — the control does not exist in our systems. |
| Responsible disclosure | Open | We invite security researchers to test us and report issues (see below). Scrutiny makes the product safer. |
| Independent security audit | On our roadmap | We intend to commission a third-party security assessment and publish its results as we scale. We will report our progress here rather than claim it before it's done. |
| SOC 2 & ISO 27001 | On our roadmap | Formal certification is a significant investment we are planning for a later stage of the company. We will not imply we hold a certification we haven't earned. |
We're early, and we would rather you know it. This table will change as we do — and every change on it will be something we actually completed.
Trust without accountability is just branding. So: