SevinShield drives a real Chromium browser through every URL you submit, records every network call, cross-checks every domain against 254,810 live threat-intel rows, scores trust signals (domain age, MX/SPF/DMARC, look-alike domains, scam-language, crypto-wallet blacklists), and tells you exactly what fired and why. No black box, no inflated numbers — and the public blocklist only contains hosts we confirmed ourselves.
Early-access pricing locks in for the first year. The product still has rough edges — we're documenting every fix in /docs.
Three real scans we ran. Click any card to open the full report — including the screenshot Chromium captured, every finding with evidence, and the new scam & trust signals panel.
A real publisher with proper IAB TCF v2 consent detected, low-severity ad-trackers correctly classified as compliance signals (not malware). The kind of site you DON'T want flagged as malicious — and SevinShield agrees.
Looks legitimate at first glance, but missing the consent banner expected on an EU persona. 3 third-party trackers (Google Analytics, Meta Pixel, Cloudflare Insights) detected. Suspicious for compliance, not for fraud.
A real PhishTank-listed Binance impersonator. Caught by our intel feed AND by the new lookalike detector (brand-in-stem) AND by scam-language heuristics. Trust deficit 6+/10 → low_trust_aggregate finding fired.
Submit a URL, we drive a real Chromium browser through it with one of eight device personas (iPhone, Pixel, desktop Chrome / Safari / Edge — in EN-US, PL, DE, RO locales). Every network call, cookie, redirect and script execution is recorded.
From the dashboard, our API, or scheduled rescans on the domains you've registered.
Playwright + Chromium opens the page with a real device persona. Full DOM, real JS execution, full cookie storage — nothing emulated.
Every loaded domain is checked against URLhaus, OpenPhish, MalwareBazaar, Google Safe Browsing and our heuristic detectors.
Per-finding evidence, screenshots, full request chain, downloadable JSON / PDF. Aggregated into your tenant blocklist feed.
Each detection is a rule with a fingerprint, so you can read why we flagged something — not just a score.
Loaded host matches URLhaus / OpenPhish / PhishTank / Safe Browsing.
location.replace() to off-host within 3 seconds of load.
Known miner scripts (CoinHive forks, JSEcoin and friends) executed.
window.open with negative coords, hidden focus, or auto-fire.
Auto-requests for notifications / geolocation without user gesture.
Heuristic: 95% non-printable in <script> + eval pattern.
Display URL differs significantly from click-through final URL.
>10 distinct tracking pixels on one page.
No IAB TCF / OneTrust / Cookiebot / GPP signal detected on EU persona.
NSFW / gambling / weapons content detected in screenshots.
Cross-referenced against StevenBlack hosts, EasyList, AdGuard DNS filter.
New CT-log certificate on a look-alike of a known brand.
No "contact sales" theatre. Everything is published — pick the tier, pay, get scans.
Same four verticals every grown-up ad-quality vendor serves. We start with the SMB end of each — fair price, real product.
Block malvertising and offensive ads in real time. Subscribe to your blocklist feed from your ad server.
QA every creative before it ships. Categorise and identify regulated content.
Verify monetisation partners aren't sneaking misleading offers, popunders or geo-fenced bad creatives.
Defend your landing pages and supply chain against impersonation domains and data leaks.