// technical buyer's security postureWhat we'll commit to in writing.
If you're evaluating BD Shield as a vendor for an agency, an enterprise WordPress site, or a regulated business, here's the posture our team commits to. No NDA, no sales call, no "let's hop on a quick demo."
last reviewed 2026-06-08
review cadence quarterly
disclosure hello@getbdshield.com
// data residencyYour data never leaves your host.
Plugins process site content, user data and security events on your server. We never sync site data to BD infrastructure. The only outbound call is your license check.
verified · audit-friendly // telemetryNo third-party telemetry.
Plugins don't ship analytics SDKs, fingerprinting libraries, or usage trackers. We don't know how many of your forms got submissions, and we don't want to. Grep your wp-content — you won't find them.
verified · grep-checkable // code transparencyAudit-ready code.
Plugins ship un-obfuscated PHP, organized by class with predictable naming. Hand a license to your security reviewer and they can read the firewall logic in an afternoon.
verified · open any .php // review cadenceQuarterly security review.
Every quarter, our engineers re-audit the firewall, the malware scanner and the auth flows. Findings get patched in the next release. We publish the cadence; enterprise customers can request the summary.
cadence published · external pending // update integritySigned download tokens.
Plugin downloads from our license server use signed, time-limited tokens tied to your license. No anonymous public URLs that hostile actors can fingerprint.
verified · per-request tokens // dependenciesPinned dependencies.
Plugins vendor their dependencies at fixed versions. We don't load third-party JavaScript from CDNs at runtime, ever. What you install is what runs.
verified · single-tree codebase // refund30-day refund, no friction.
If a plugin doesn't fit, email us inside 30 days. We refund the license. No churn-survey, no retention call, no "let me transfer you to my manager."
verified · billing policy // support modelReal-engineer support.
Tickets land with engineers, not a tier-1 queue. The person replying has commit access to the plugin you're asking about. Most replies inside a day; complex tickets inside three.
verified · last 90 days // what we don't have yetNo SOC 2. No ISO 27001. Not yet.
Honest about gaps. We're a small workshop, not an enterprise vendor. If your security team needs those reports today, we're not the supplier — and we'll say so on the call, not after the invoice.
known gap · roadmap dependent