AI in ShieldWave
Version of 29 September 2026
This page explains what ShieldWave uses artificial intelligence (AI) for, which data reach it and how you can recognise text written by AI. ShieldWave is run by Radosław Fedorczuk, trading as ENSOMEDIA Radosław Fedorczuk, ul. Chorwacka 33/42, 51-107 Wrocław, Poland, tax number (NIP) 8952195742, EU VAT number PL8952195742, business register number (REGON) 381626230, entered in the Polish Central Register and Information on Economic Activity (CEIDG), "ENSOMEDIA" or "we" below.
On this page a "finding" is a problem the scanner found on the checked site, and "severity" is how serious that problem is.
1. What AI does
1.1 In checks ordered from an account
When the AI service is available, in checks ordered from an account AI:
- explains the findings in plain language and writes the summary of the report;
- drafts repair instructions;
- reviews the severity of the findings and may change it;
- marks findings it considers a likely false alarm and lowers their severity; the scanner's original result is kept and shown;
- describes possible business and legal consequences of findings; this is for information and is not legal advice (point 8.1 of the Terms of Service);
- suggests which tests suit the site's technology;
- translates into the language of the report the descriptions of known vulnerabilities and other passages the scanner produced only in English.
While control of the domain is not confirmed, AI only writes the texts of the report: it does not review the severity of findings and does not suggest tests.
A second AI model checks the text written by AI by comparing it with the data of the check.
1.2 In the WordPress plugin
In the plugin "Ensomedia Security powered by shieldwave.io" AI works only when the site's administrator has switched it on. It then gives a second opinion on a file that the plugin's scanner could not settle.
2. What AI does not do
- It does not talk to you: ShieldWave has no AI chat.
- It makes no decisions about people.
- It does not look for problems: the scanner's rules do. AI may only suggest which tests to run.
- It never edits, quarantines, deletes or blocks anything.
- In the plugin it does not lower a "malicious" verdict given by the scanner's rules. It may lower an unconfirmed finding by one step at most, and never below medium severity.
- The demonstration check on the home page and the four free tools use no AI.
3. How to recognise AI text
- We mark text written by AI with a visible "AI" label in the app, in reports and in the plugin.
- By 2 December 2026 we will add machine-readable marks to reports and to API responses.
- Customers may not remove the AI marks from reports, also not from reports with their own logo.
4. Which data AI uses
4.1 Checks ordered from an account
| Function | Data |
|---|---|
| Explanations, report summary, repair instructions, severity review | the domain, the type of platform and server, technical findings: type, severity, address, headers and up to 500 characters of evidence per finding |
| Fitting the explanations to the kind of business | an excerpt of the home page: up to 3,000 characters of text with the title, description, headings and footer |
| Business and legal consequences | findings, domain and home page excerpt |
| Translation | the passages of the report that need translating |
| Check of the AI text | the text written by AI and the data of the check it relates to |
Evidence is an excerpt of what the site returned to the scanner. The evidence and the home page excerpt can contain names, e-mail addresses or other contact details that the site publishes.
4.2 The WordPress plugin
The plugin sends our server an excerpt of the file of up to 6,000 characters. Before sending it, the plugin removes passwords, keys, e-mail addresses and the site's host name. Other web addresses and IP addresses in the excerpt are not removed. The plugin also sends the file's fingerprints (sha256 and md5), its size, the folder name of the component, the rule identifiers, the site's language setting, the plugin version and a salted hash of the site.
We pass on to our AI provider the excerpt, the type of file, the name of the component, the plugin scanner's first assessment, the rule identifiers and the language for the answer. The fingerprints, the size, the plugin version and the site hash stay with us.
4.3 What we never send
Your account data, your password and payment data never reach AI. The plugin never sends the files wp-config.php or .env.
5. Who processes the data and where
The data described in section 4 are processed by our AI provider, on our behalf, on servers in the United States. The provider's name and details are in the list Subprocessors and recipients.
For the transfer outside the European Economic Area we rely on the standard contractual clauses adopted by the European Commission (Commission Implementing Decision (EU) 2021/914). On request we will send you a copy of these safeguards.
Our AI provider is contractually barred from using this data to train models. It does not store it, except for up to 30 days when it investigates a reliability problem or suspected abuse.
6. How long we keep the data
- We keep AI answers in a cache so that the same question is not sent twice: up to 1 hour in the server's memory and up to 24 hours in the database.
- What AI added to the results of a check, for example explanations or a changed severity, we keep together with the check, for as long as the Privacy Policy says.
- Opinions on plugin files are kept without a time limit by the file's fingerprint and are reused for the same file on other sites. We store the fingerprint and the opinion, without the name of the site. We also record that a file with that fingerprint appeared on a site identified by a salted hash; we delete that record after 12 months.
- The plugin keeps up to 2,000 recent opinions in the database of your WordPress site.
7. Accuracy: what to check yourself
AI can be wrong, also when it sounds sure. Treat its text as guidance:
- before you change anything on your site, check the instruction written by AI and try it on a copy of the site first;
- check a finding marked as a likely false alarm yourself; the scanner's original result is shown with the finding;
- the plugin's AI opinion is a second opinion: you decide what to do with the file.
The descriptions of legal consequences in a report are for information and are not legal advice. When the AI service is not available, the report contains our prepared standard texts in place of AI text. Our liability for the service is set out in the Terms of Service.
8. Our legal position
8.1 The Artificial Intelligence Act
Under Regulation (EU) 2024/1689 (the Artificial Intelligence Act) we are the provider of an AI system built on another company's general-purpose AI model. We are not the provider of that model. Our system is not a high-risk system and serves no prohibited practice.
We have the transparency duties of Article 50 of that Regulation, which is why we mark AI text as section 3 describes. For systems placed on the market before 2 August 2026, machine-readable marks are required from 2 December 2026 (Regulation (EU) 2026/1744). For the texts we publish ourselves (section 9) we are a deployer of an AI system.
8.2 Personal data
Where we decide on the purposes of processing (we are the controller), the legal basis for processing data with AI is our contract with you (Article 6(1)(b) GDPR). For data of other people that appear on the checked site, the basis is our legitimate interest in performing the check that was ordered and in producing a report that can be understood (Article 6(1)(f) GDPR). When a business customer or a sole trader with consumer rights orders the check, we process these data on its behalf under the Data Processing Agreement.
AI makes no decisions about anyone based solely on automated processing within the meaning of Article 22 GDPR. More information is in the Privacy Policy.
8.3 Complaints
You can write to us first: support@shieldwave.io.
A complaint about an AI system can be lodged with the Commission for the Development and Security of Artificial Intelligence (Komisja Rozwoju i Bezpieczeństwa Sztucznej Inteligencji, KRiBSI), the Polish authority supervising AI (Article 59 of the Polish Act of 3 July 2026 on artificial intelligence systems; the rules on complaints take effect on 28 October 2026).
A complaint about personal data can be lodged with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stanisława Moniuszki 1A, 00-014 Warszawa, Poland.
9. Texts we publish
We write the blog articles and the studies of ShieldWave with the help of AI. Before publication a person checks every text, including its facts. Editorial responsibility for these texts lies with ENSOMEDIA Radosław Fedorczuk.
10. Contact
Send questions about AI in ShieldWave to support@shieldwave.io. Our full company details are on the page Legal notice.
11. Change history
- 29 September 2026: first version of this page. Before, information on AI was given only in the privacy policy and the list of subprocessors of February 2026.