CloviShield changes your site — so we built it to be safe by default
Remediation means modifying real files on a live site. Every CloviShield action is consent-first, scoped to you alone, fully logged, and completely reversible. Nothing is ever permanently deleted without a restore path.
Consent & Authorization
You must own or be authorized to manage any site you connect. CloviShield never acts on a site without you.
- Site ownership verification before any connection
- Explicit, per-action consent — you approve each fix before it runs
- Findings are presented for review; nothing executes silently
- Authorization can be revoked at any time
Per-User Isolation
Your sites, jobs, quarantine, and reports belong to you and only you.
- Every action is scoped by your authenticated account
- No shared or global data across customers
- Signed, short-lived access for each operation
- A new account starts completely empty
Audit Trail
Every change is recorded so you always know exactly what happened, when, and why.
- Each fix is timestamped and attributed
- Before/after state captured for every change
- Exportable history for compliance and handover
- Reversible from the same record
Quarantine, Not Delete
Suspicious files are moved to a secure vault — never destroyed.
- Flagged files isolated in a private quarantine vault
- No permanent deletion as part of remediation
- 30-day restore window on every quarantined item
- Restore a file with one click if a finding was a false positive
Rollback & Reversibility
If a fix isn't what you expected, undo it instantly.
- One-click undo on any applied change
- Restore points captured before each clean job
- Reversibility verified before a job is marked complete
Gated Execution
Fixes run through a security-vetted, metered execution layer — not arbitrary code on your server.
- Actions limited to a vetted remediation set
- Metered and rate-limited execution
- Least-privilege access for each operation
Data Handling
Your files and findings are stored privately and scoped to your account.
- Private storage — never a public bucket
- Per-user, per-site scoping at the storage layer
- Signed access; no open or shared file paths
- See our Data Handling policy
Detect, Then Fix — One Flow
CloviScan detects issues and CloviShield fixes them, with the same consent and audit guarantees from start to finish.
- Scan results feed directly into a reviewable fix plan
- You approve before anything is modified
- Clean report verifies the site afterward
Your authorization is required
CloviShield will not scan, modify, quarantine, or clean any site you have not verified you own or are authorized to manage. Connecting a site you don't control is a violation of our Terms. Authorization is requested up front and confirmed for each remediation action.
Safe by design. Reversible by default.
Start protecting your site with consent-first, fully-audited remediation.