Security & Trust

CloviShield changes your site — so we built it to be safe by default

Remediation means modifying real files on a live site. Every CloviShield action is consent-first, scoped to you alone, fully logged, and completely reversible. Nothing is ever permanently deleted without a restore path.

Consent & Authorization

You must own or be authorized to manage any site you connect. CloviShield never acts on a site without you.

  • Site ownership verification before any connection
  • Explicit, per-action consent — you approve each fix before it runs
  • Findings are presented for review; nothing executes silently
  • Authorization can be revoked at any time

Per-User Isolation

Your sites, jobs, quarantine, and reports belong to you and only you.

  • Every action is scoped by your authenticated account
  • No shared or global data across customers
  • Signed, short-lived access for each operation
  • A new account starts completely empty

Audit Trail

Every change is recorded so you always know exactly what happened, when, and why.

  • Each fix is timestamped and attributed
  • Before/after state captured for every change
  • Exportable history for compliance and handover
  • Reversible from the same record

Quarantine, Not Delete

Suspicious files are moved to a secure vault — never destroyed.

  • Flagged files isolated in a private quarantine vault
  • No permanent deletion as part of remediation
  • 30-day restore window on every quarantined item
  • Restore a file with one click if a finding was a false positive

Rollback & Reversibility

If a fix isn't what you expected, undo it instantly.

  • One-click undo on any applied change
  • Restore points captured before each clean job
  • Reversibility verified before a job is marked complete

Gated Execution

Fixes run through a security-vetted, metered execution layer — not arbitrary code on your server.

  • Actions limited to a vetted remediation set
  • Metered and rate-limited execution
  • Least-privilege access for each operation

Data Handling

Your files and findings are stored privately and scoped to your account.

  • Private storage — never a public bucket
  • Per-user, per-site scoping at the storage layer
  • Signed access; no open or shared file paths
  • See our Data Handling policy

Detect, Then Fix — One Flow

CloviScan detects issues and CloviShield fixes them, with the same consent and audit guarantees from start to finish.

  • Scan results feed directly into a reviewable fix plan
  • You approve before anything is modified
  • Clean report verifies the site afterward

Your authorization is required

CloviShield will not scan, modify, quarantine, or clean any site you have not verified you own or are authorized to manage. Connecting a site you don't control is a violation of our Terms. Authorization is requested up front and confirmed for each remediation action.

Safe by design. Reversible by default.

Start protecting your site with consent-first, fully-audited remediation.