METHOD

How a Shield Engagement Runs

Intake — what we ask for, and what we refuse

A Shield engagement inherits the Mirror and Lockdown intake whole: the anchor identifiers, the jurisdiction and language scoping, the signed engagement-specific consent, the identity check confirming that the person commissioning the work is its subject. The Mirror and Lockdown walk-throughs set that out and it is not repeated here. What follows is what the Shield adds. Each item exists for the same reason: the work is bounded, and intake is where the boundary gets drawn.

Where a client believes a threat is already underway, we ask for their account of it. We record it as their account. What they have seen, when, on which platforms. Any messages, profiles or contact attempts they have kept. Dates matter more than impressions here, because a sequence can be checked and a feeling cannot. Nothing in that account is treated as established at this stage. It sets the direction of the investigation without settling its conclusions.

Analysing a thirty-day window of the client's public activity falls inside the engagement consent, because it reads a record that already exists. Observing that activity as it happens does not. Live observation is a different act from reading an archive. Where a case calls for it, it is authorised separately and for a fixed period, and what that authorisation has to cover depends on the case, the jurisdiction and the purpose. Most prevention cases never need one. The distinction is drawn at intake rather than assumed, because the two produce different obligations and only one of them involves watching a person.

Household scope works the way it does in a Mirror, and for the same reason. Where a source already names a member of the client's household, we can record that it does so. We do not search that person. Their consent is not the client's to give. A Shield engagement does not acquire the right to it by being about a threat. Where a family member's own exposure needs mapping, that is a separate piece of work with its own subject, its own consent and its own fee.

Some things we do not ask for and will not accept: passwords, PIN codes, two-factor authentication codes, passport or national identity numbers, bank or card details. We do not want access to accounts, devices or mailboxes. If any of it arrives in a message to us, it is deleted and we say that it was. What we want is narrower and duller — the username rather than the password, the handle attached to an account so that it can be followed through public sources.

There is also one request that runs the other way. For an active threat, do not delete anything yet. The instinct on discovering a hostile profile is to scrub, block and lock down, and it is a reasonable instinct that destroys the record. What is visible now is what an adversary has been working from, and can only be documented while it is still there. Reduction comes later in the engagement, after the picture is captured rather than before.

The first decision: active threat, or prevention

Everything downstream turns on one question, settled at intake rather than assumed: is something already happening, or is the concern that it might?

A client's own description is where that question starts, not where it ends. People misjudge it in both directions. Someone receiving well-timed messages from an account that seems to know their schedule may describe themselves as merely cautious. Someone whose exposure is unremarkable may be certain they have been singled out. Neither reading is careless. Both are made from inside the situation, where a single unsettling message and a sustained campaign feel much the same and look nothing alike written down.

So the client's account is recorded as their account, and where a threat may be active the engagement runs on two tracks at once. What the client believes is happening governs the immediate precautions, because several of those are quick, reversible and worth taking before anything is proven. What the investigation establishes governs the conclusions. The two are kept apart deliberately. Treating a belief as a finding puts an unverified theory into a document that other people may later read.

The switch changes three things. It decides whether forward observation is justified at all, and therefore whether a separate consent is needed. It decides sequencing, because an active case front-loads the work that reduces immediate risk while a prevention case can run in the order that produces the clearest picture. And it decides what the report is for: a record shaped for escalation, or a set of gaps to close.

It is also revisable. A prevention engagement that surfaces a pattern of coordinated attention becomes an active-threat engagement, and the scope changes with it. That is a re-scope discussed with the client, not a quiet expansion of the work.

One boundary belongs here rather than in the report. Clients almost always want to know who. Open sources rarely answer that. We can establish what is visible, what an approach would have had to work with, and whether the behaviour across accounts fits a coordinated pattern. Attributing it to a named person is a different kind of claim, and one that public information usually cannot support. Saying so early is part of the scoping, because an engagement sold on a promise of identification would be sold on something we cannot control.

A Shield engagement runs on three separate authorisations, and keeping them separate is the point.

The engagement consent covers searching public sources for records associated with the client's own identifiers. It is signed before any search begins, it names the engagement, and it expires with it. Forward observation, where a case warrants it, is authorised on its own and runs for a fixed thirty days. A family member whose exposure needs mapping is a third authorisation, given by that person, for work with their own subject and their own fee.

Underneath all three sits the identity check: confirmation that the person commissioning an investigation into someone is that someone. A service that skipped this would be a service for investigating other people, sold to whoever asked.

None of the three authorises what clients occasionally assume they do. They do not give us access to accounts, devices or mailboxes, and nothing in the engagement asks for it. They do not extend to anyone the client has not the standing to speak for. They do not survive delivery, which is why collected data is purged within forty-eight hours rather than retained against a future engagement.

The sharpest thing consent rules out follows directly from an active-threat case. A client who believes someone is targeting them has an obvious question about that person, and an obvious request follows from it: look at them, not at me. It is a reasonable thing to want and we do not do it. A named individual who has not authorised anything is not a permissible subject, however good the reason sounds and however plausible the client's suspicion turns out to be.

Refusing that request is the same act that makes the client's own report worth having. A firm that would investigate a third party on a client's say-so is a firm that would investigate the client on someone else's. The restraint is not adjacent to the service. It is the thing being sold.

Which is where the asymmetry lands. Whoever is building a profile of the client operates under none of this. They need no authorisation, no identity check and no expiry, and they can keep whatever they gather for as long as they like. That freedom is precisely why their work has no provenance and no standing. Nobody could hand it to a lawyer or a police officer and expect it to carry weight, because there is no account of where it came from or what permitted it. A Shield engagement gives that freedom up on purpose, and what it produces instead is a record with a known origin, an authorising subject and a defined end.

How a finding becomes a judgement

A finding is not a fact about a person. It is an artefact, a record of where it came from, and a statement of what it permits us to say. Most of the discipline sits in the third part.

The first two are procedural. Provenance is recorded when something is collected rather than reconstructed afterwards, because afterwards is too late: a screenshot with no source, no date and no route back to it is an assertion. Confidence scoring is inherited from the Mirror, where a single uncorroborated source is marked as one and independent corroboration is what lifts a finding above it.

What the Shield adds is the question of what a combination licenses, because on their own most artefacts license almost nothing.

A photograph of someone outside an office building is a photograph. It becomes something else when it sits beside a court listing naming them in a commercial dispute, an interview in which they mention keeping Tuesday mornings clear, and a public schedule that is otherwise dense and specific on every weekday of the year. Two of those they published themselves. One was written about them. One is a matter of public record. Not one of the four is sensitive. Nobody disclosed a legal appointment.

Read together they produce one: an address, a morning, a recurrence and a plausible reason. The blank Tuesday is doing as much work as the photograph, because a gap in a documented week is itself a documented thing. And once that reading exists, the next held Tuesday is no longer empty space in a diary. It is a prediction.

The disclosure was never made. It was assembled.

That is the analytical work, and why an inventory of exposures is not an assessment. The way separate fragments compound into something none of them contains is the mosaic effect. The value is created at the joins. So the link is treated as the finding: it is stated explicitly, the artefacts under it are listed, and the reasoning from one to the other is written out rather than implied.

Which is also where this goes wrong. Fragments combine easily and combine wrongly, and an assembled story feels stronger than any of its parts. A chain of inference is therefore reported as a chain of inference, with the links visible, so that the client can disagree with a step. A conclusion the reader cannot take apart is a conclusion they have to take on trust, and trust is the wrong currency here.

Patterns also expire. An artefact proves a pattern existed at a date, not that it holds now. Someone may have changed employer, stopped attending, moved, or simply broken the habit. Reading a routine as a protective-intelligence question rather than a list of sightings is what makes that judgement possible. So a pattern carries the period it was observed over and a plain statement of whether anything more recent supports it. A prediction built on a routine that lapsed two years ago is not a weak finding. It is a wrong one, and worse than useless, because it points attention away from the exposure that is live.

The same care governs the difference between what is visible and what is inferred. A people-search profile listing an address is directly observable. We can open it, date it, and say precisely what it shows, because it is published. Which commercial data brokers hold records on that same person is not observable from outside at all. Those holdings are sold business to business and are not exposed for inspection, so no amount of searching establishes them. We can say a profile is the shape such records are typically built from. We cannot say who holds one, and an engagement implying otherwise would be inventing the most reassuring part of its own report.

Absence is treated the same way. Not finding something is a statement about a search, not about the world. We document what was looked for, where and on what date. We do not certify that nothing exists, because open sources cannot support that claim.

The practical effect is that much of what an investigation turns up never reaches the report. An artefact that cannot be sourced, dated or checked is not a weak finding to be hedged. It is not a finding.

The thirty-day window — baseline, then deviation

Every Shield engagement analyses a thirty-day window of the client's publicly visible activity. Posts, check-ins, tagged photographs, replies, the appearances and filings that carry dates. Read individually these are unremarkable. Read as a month, they describe a routine: where the client reliably is, on which days, with whom, and which of those patterns a stranger could predict without ever contacting them.

That analysis is retrospective. The month has already happened and its traces are already public, so the work is reading a record rather than observing a person. It also means a client does not wait thirty days for an answer.

For a prevention case the window is where the engagement does its thinking. Once the routine is legible, the question becomes how an approach would be framed against it, which recurring detail would make a stranger sound like they already knew the client, and which of those details can be removed or made less regular. The output is a set of gaps to close, not a forecast of who might use them.

An active threat adds the second half. Here the client wants to know whether something is happening now, and that question cannot be answered without knowing what normal looks like first. Deviation is only measurable against a baseline. So the window is analysed to establish the pattern, and observation forward runs against that pattern rather than against an impression of it. This is the half that requires its own consent, and the half that ends on a date.

What the window does not cover is worth stating plainly. It reads what is publicly visible. It does not reach private accounts, direct messages, devices or anything behind a login, and no part of the engagement asks for access to them. It is not continuous. There is no real-time alerting, and nothing runs on after the engagement closes. The limits of anything that watches a list you supplied are a separate question. Thirty days is a sample deliberately, chosen to be long enough for a weekly rhythm to show and short enough to stay a defined piece of work.

Keeping that cycle running afterwards is a different job with a different shape. Where a client wants it carried forward, that is Guardian Executive.

What gets reduced, and what cannot be

Reduction in a Shield engagement is driven by the threat picture rather than by completeness. The question is not how many records exist but which of them make an approach easier, and those are addressed first. Where the objective is an exhaustive removal campaign across broker surfaces, that is a different service with a different shape.

Everything we act on rests on the client's own standing. Their accounts, their data, their opt-out rights. Nothing in the engagement depends on our authority, because we have none. We prepare and execute requests the client is entitled to make.

What that reaches divides in three.

Some things close cleanly and stay closed. Account recovery routes pointing at dead mailboxes, old sessions, weak security questions, over-permissive profile settings, reused credentials sitting in stealer-log corpora. These are decisions the client controls, and once changed they do not undo themselves.

Some things degrade rather than close. People-search profiles come down on request and regenerate when the underlying feed refreshes, which is what independent testing of removal services keeps measuring. Suppression there is real and it is a cycle, not a fix, which is the honest reason ongoing work exists at all.

Some things do not move. Company filings, property records, court records, licensing registers. These are authoritative by design and their permanence is the point of them. Content another person wrote and published about the client is also outside this work, whatever it says. Removing what a third party lawfully published is neither something we do nor something we can promise.

One reduction has nothing to do with records. Where the window analysis shows a routine that a stranger could predict, the response is to make it less predictable. That is a change in behaviour rather than in data, and the only lever in the engagement that closes a gap the client cannot delete.

None of this produces invisibility. An engagement should not be sold as though it might. What it produces is a smaller and staler set of material for an approach to be built from. The claim is about difficulty, not disappearance.

Where the engagement stops

The Shield is a digital investigation, and several things that sit next to it are not part of it. It is not a penetration test or a network assessment, both of which examine systems rather than a person's exposure. It is not incident response. It is not physical security. It is not a criminal investigation, and no private engagement is.

Those are boundaries on the service. There is a second kind, set per engagement, and it is agreed before any search begins rather than left to an analyst's discretion in the field. Scope is defined by area. An engagement scoped to a client's professional life examines their professional life: roles, filings, appearances, affiliations and the exposure those create. It does not extend into their family, their relationships or their private activity on the grounds that those turned out to be reachable. Reachable and in scope are different things, and which is which is settled at intake.

That boundary produces a decision rather than a silence. Where something outside the agreed area looks relevant to the threat picture, we report that it exists and that it falls outside scope, and the client decides whether to extend. We do not quietly look into it, and we do not quietly leave it out. Either would put our judgement in place of theirs on a question that is properly theirs.

The categorical boundaries hold even when a case argues for crossing them. If the picture that emerges suggests a credible physical threat, the engagement says so plainly and says it early, and the matter belongs with police. We do not treat that as a failure of scope or an upsell opportunity. It is the point at which someone with powers we do not have should be involved.

We also do not approach the other side. Nobody is contacted, warned, engaged or negotiated with on a client's behalf. An analyst who introduces themselves to a suspected harasser has told that person they are being looked at, which changes their behaviour and destroys the value of everything gathered so far. The work stays observational for the same reason it stays consented: both are what keep the record clean, and both are what hold research on the right side of the line into surveillance.

"Documented for escalation" means less than it sounds like it means. Findings are dated, sourced and structured so that a reader who was not part of the investigation can follow them without us: what was observed, where it came from, when it was collected, and what it does and does not support. That is a record a lawyer or an officer can work from. The form it takes varies with the case, the jurisdiction and who it is going to, so it is agreed rather than standardised. It is not a legal opinion. It does not assert what any of it proves, and it is no substitute for advice from someone qualified to give it.

The report belongs to the client. That matters more than it first appears, because a good assessment sometimes surfaces things they had chosen not to make public, assembled from pieces they never thought of as connected. Nobody else receives it by default. Who sees it, including whether any of it goes to police at all, is the client's decision and stays theirs.

When the Shield is the wrong tool

The Shield is the largest of the personal engagements and it is not the right starting point for most people.

If nothing has happened and the question is simply what is findable, that is the Mirror at €595. It is the same investigative method without the threat layers, and the honest first step for anyone whose concern is general rather than specific.

If the worry is credentials, breaches and what is circulating in stealer-log corpora, that is the Lockdown at €995.

If the objective is a thorough removal campaign across broker and people-search surfaces, run to a schedule and re-checked, that is the Eraser at €3,800. The Shield reduces what the threat picture makes urgent. It is not a removal programme wearing a different name.

If the concern is how a person reads to anyone who looks them up, rather than what an adversary could do with it, that is Reputation Analysis at €1,450.

If the people needing protection are an organisation's, commissioned by that organisation, that is the Corporate Audit from €5,000.

And if the request is to investigate somebody else, no service here covers it, whatever the circumstances.

After the engagement — the Guardian question

A Shield engagement is point-in-time by design. It establishes which approaches a person is open to, at a moment. That moment does not hold still. People-search profiles regenerate when their feeds refresh. Credentials resurface in new corpora. Roles change, filings are made, appearances accumulate, and a routine that was varied deliberately drifts back toward regular.

None of that is a defect in the work. It is what makes the work a baseline rather than a conclusion.

Whether a client wants that baseline carried forward is a separate decision, raised at the end of the engagement rather than folded into it. The retained form is Guardian Executive, from €9,600 a year, scoped to the person.

It is worth being precise about what a retainer is and is not. It is a defined cadence of re-checking with defined response windows and analyst hours held open. It is not continuous surveillance of anyone, it does not watch a person's accounts in real time, it does not involve device access or forensics, and it carries no guarantee that anything removed stays removed. A retainer that promised those things would be promising what nobody can deliver, which is a poor foundation for a relationship measured in years.

For many clients the right answer is no, or not yet. A hardened surface holds for a while on its own. A client who does not need managing should not be sold management.

Closing

An engagement of this kind is easy to judge by the wrong measure. A long report with many findings looks thorough. What actually decides whether it is any use is narrower: whether each item can be traced back to where it came from, whether we were permitted to gather it, and whether a reader can follow the reasoning without taking our word for anything.

Whoever might be assembling a profile of the client works under none of those requirements and is not slowed by them. They can look where we will not, keep what we delete, and approach people we have no standing to contact. That asymmetry does not close. Nothing here has pretended otherwise.

It is also what separates the two files. Theirs is knowledge about a person, held privately, answerable to no one, and worth very little the moment it has to be shown to somebody else. Ours is a record with a subject who authorised it, an origin for every line and a date on which it stops. One of those can be acted on. The other can only be used.

The Shield does not make anyone invisible and does not claim to. It establishes what an approach to a particular person would have to be built from, closes what closes, degrades what degrades, and says plainly which parts will not move. That is a smaller promise than this category usually makes. It is also one that can be kept.

Sources

  1. National Protective Security Authority, Understanding Your Level of Risk (updated 22 April 2026), sections 2 and 4. NPSA guidance addresses people facing heightened threats to their personal safety and security; it does not endorse Privacy Insight Solutions or define the scope of this service.
  2. MITRE ATT&CK, Gather Victim Identity Information (T1589) and Search Open Websites/Domains: Social Media (T1593.001).
  3. He, J., Snyder, P., Haddadi, H., Bustamante, F. E., Tyson, G. “Measuring the Accuracy and Effectiveness of PII Removal Services.” Proceedings on Privacy Enhancing Technologies 2025(4), 166–182. doi:10.56553/popets-2025-0125. Removal figures measured across 71 participants and four services; 48.2% of identified records were removed within the first month, meaning the majority were not.

This article is analysis, not legal advice.

If this is your situation

If you’re facing an active threat, the Shield engagement responds within hours.

Protect a targeted person Request a free Snapshot Scan

Share this briefing

If this was useful, sharing it helps others protect themselves. It also helps keep the intelligence briefings free.

Or get the quarterly intelligence brief — significant breaches, OSINT technique shifts, and executive privacy risks, once a quarter. Read the briefing →