Security and data handling
How ShadowScore handles investigation data
ShadowScore uses limited business information and submitted evidence to prepare source-backed risk assessments.
01
What we collect
- Business names, domains, and identifiers
- Evidence and context submitted for an investigation
- Public records and visible operational signals
02
What we never collect
- Marketplace or payment account passwords
- Card numbers, CVV codes, or banking credentials
- Credentials for third-party business systems
03
How your data is used
- Resolve the business identity under review
- Organize evidence and produce the requested report
- Maintain report and investigation history in your workspace
04
Security principles
- Collect only the information needed for the review
- Keep evidence context and sources traceable
- Restrict access to private workspace records
- Separate observed facts from analysis and confidence