OCTOBER UPDATE: FASTER WEBSITES, SMOOTHER VERIFICATION AND PASSKEY SIGN-IN.Read the update Sign in
Changelog

What's New at Shieldify

Customer-facing improvements, newest first.

1 October 2026Improvements since our 27 September 2026 update.

Faster Websites

  • Pages served through Shieldify now load noticeably faster: Shieldify keeps its connections to your server open and reuses them instead of opening a new connection for every request.
  • Pages, stylesheets and scripts are now compressed on the way to your visitors, so they download faster.
  • Your server now receives far fewer new connections from Shieldify, which lowers its load during busy periods.
  • If your server cannot be reached, visitors now see an error page after 15 seconds instead of waiting up to a minute.

Smoother Visitor Verification

  • Fixed an issue where a form submitted after a few minutes on a website (for example sign-in, registration, checkout or comments) could be lost, requiring visitors to submit it again.
  • Many visitors and browsers sharing one network, such as an office, school or mobile carrier, can now complete verification at the same time.
  • Visitors who open many pages quickly are no longer mistakenly blocked for a short time.
  • The CAPTCHA now recovers from brief connection problems and returns visitors to the exact page they were on.
  • Forms sent to the HTTP address of a website with Force SSL now keep their content when redirected to HTTPS.
  • Visitors who reach a website while its setup is still completing can now pass verification instead of seeing the check repeatedly.

Search Engines

  • Major search engine crawlers such as Googlebot and Bingbot are now recognized reliably and are not asked to verify, protecting your search visibility. Bots that only pretend to be search engines are still checked.
  • The list of official search engine addresses is now refreshed automatically every week.

Stronger Protection During Attacks

  • Improved the stability and speed of protection during very large attacks.
  • Attacks from very large numbers of addresses are now blocked more completely.
  • A single attacker can no longer use up verification capacity and keep real visitors from verifying.
  • SSL certificates can now be issued and renewed even while a website is under attack.
  • Strengthened network-level DDoS protection in front of Shieldify.
  • Added automatic monitoring of the services behind visitor verification, so problems are detected and resolved faster.

Private Pages

  • Private page rules now match addresses more reliably, including variations in letter case and trailing slashes.
  • Improved the security of the private page access request page shown on your website.

Account and Panel Security

  • You can now sign in with a passkey, such as Face ID, Touch ID, Windows Hello or a security key. Add one from your Profile; password sign-in remains available.
  • Two-factor authentication codes can now be used only once.
  • Limited how many verification emails can be sent to an account, protecting inboxes from email flooding.
  • The panel can no longer be embedded in other websites, protecting against click-tricking attacks.
  • Website server addresses are now validated more strictly.

Safer Website Settings

  • A settings change that cannot be applied is now rolled back automatically, without affecting your other settings or websites.
  • Protection settings such as rate limits now have clear allowed ranges.
  • Deleting a website now also removes its SSL certificate.
  • Panel tools such as log search, DNS checks, cache purge and notification tests now have fair-use limits, keeping the panel fast for everyone.

Payments

  • Prices and checkout load more reliably, with a retry option when a connection is slow.

Refreshed Look

  • New Shieldify logo and color palette across the website, the panel and the verification pages shown to your visitors.

More Secure HTTPS

  • HTTPS connections now follow current security recommendations, and outdated encryption methods are no longer accepted. Very old browsers and devices without modern encryption support may no longer be able to connect.
27 September 2026Improvements since our 10 August 2026 update.

Smoother Visitor Verification

  • Fixed issues that could leave visitors stuck on a verification screen, especially when opening several pages or tabs at once.
  • Visitors now have more time to complete advanced verification without unexpected restarts.
  • Expired or interrupted checks recover more smoothly, making it easier to continue browsing.

Fewer Unnecessary Checks

  • Improved protection for websites that normally receive very little traffic.
  • Normal increases in visitors are less likely to trigger extra verification.
  • Protection now better distinguishes ordinary traffic growth from suspicious activity.

More Reliable Website Protection

  • Improved protection stability during busy periods and unusual traffic.
  • Updated website security rules to cover more suspicious requests.
  • Website block rules and private-page access settings are applied more consistently.

More Accurate Traffic Information

  • Improved the accuracy of traffic counts and live website status.
  • Traffic information recovers more reliably after temporary interruptions.
  • Protection alerts are delivered more reliably.

Easier Trial and Subscription Setup

  • Fixed an issue that could require a second click to start checkout when switching between trial and paid options.
  • Improved checkout recovery after interrupted attempts.
  • Made purchase assignment more reliable when connecting a plan to a website.

A Smoother Account Experience

  • Fixed intermittent errors when using the panel in several tabs.
  • Improved account verification and sign-in reliability.
  • Signed-in visitors now see their account details and a Panel shortcut on the Shieldify website, including mobile navigation.
  • Improved error messages for invalid settings and requests.

Safer Website Settings

  • Failed certificate renewals no longer remove an existing HTTPS setup or change your Force SSL preference.
  • SSL status messages now explain renewal problems more clearly.
  • Failed website connection changes restore the previous settings whenever possible, with clearer guidance when support is needed.
  • Improved validation of website connection settings.

Better Content Delivery

  • Improved static content caching while respecting private and personalized responses.
  • Fixed cases where the main domain and its www address could show incorrectly shared cached content.
10 August 2026

Better Availability During Very Large Attacks

  • Protected websites now stay fully available during exceptionally large, distributed attack waves involving many thousands of distinct sources, a scale that could previously put extra strain on the platform under extreme conditions.
  • Internal logging and monitoring during large attacks are now more efficient, so protection stays responsive and readable even at the highest observed traffic scale to date.

More Accurate Attack Wave Notifications

  • One ongoing attack is no longer reported as a stream of separate, repeated alerts; a sustained incident is now tracked and notified as a single event from start to finish.
  • Peak traffic numbers shown in attack notifications now better reflect the attack's sustained intensity instead of being skewed by a single brief traffic spike.

Increased Platform Resilience

  • Core protection processes now recover automatically from rare internal faults, reducing the chance that an isolated internal error could affect site availability.
  • Internal monitoring now detects these rare recovery events automatically, improving how quickly the operations team can respond.
22 June 2026

Shieldify Labs

  • Shieldify Labs is now part of the release validation flow for protection changes.
  • The lab checks realistic browser, API, verification, rate-limit, and origin behavior before changes are promoted.
  • This improves release confidence while keeping customer websites isolated from test traffic.

Protection and Notifications

  • Browser-like high-volume attack detection now responds earlier while keeping dedicated false-positive safeguards for clean human traffic.
  • Kernel-level quarantine now has additional reserved-address safeguards for safer Shieldify-owned lab traffic and operational testing.
  • Shieldify-owned lab traffic now follows the same website path, WAF, verification, mitigation, and origin behavior as real traffic while avoiding persistent softban or quarantine of approved lab generators.
  • Shieldify-owned lab validation can now split high-volume request tests across multiple local workers for more accurate edge-capacity measurements.
  • Shieldify Labs now supports HTTP/2-based high-volume validation to measure edge capacity with less generator-side socket overhead.
  • Shieldify-owned lab validation traffic is now reflected in live traffic metrics through the normal request path during approved edge-capacity tests.
  • Edge worker allocation now follows the full CPU capacity available on production nodes for higher L7 validation headroom.
  • High-volume protection profiling reduced internal shared-state contention in the L7 hot path, improving edge efficiency during approved Shieldify Labs capacity tests.
  • Live protection counters now use short internal batching during high-volume traffic so telemetry remains current without forcing every request to contend on the same shared state.
  • High-volume sensor observation now avoids unnecessary request parsing on lightweight skip passes while preserving detailed low-volume analysis.
  • High-volume mitigation activation now keeps exact threshold accounting while reducing redundant internal sensor work during large request floods.
  • Shieldify Labs profiling now reports per-phase L7 timing for approved capacity tests, helping isolate expensive protection stages faster.
  • Shieldify Labs can now isolate Engine challenge rendering during approved capacity validation, making it easier to measure verification overhead apart from origin throughput.
  • Enhanced mitigation has been tuned to avoid escalating on challenge volume alone when traffic appears diverse and healthy.
  • Trusted URI rules continue to support API-style bypass behavior while still contributing to protection visibility.
  • HTTPS redirect traffic is now observed before redirect handling, improving visibility into HTTP-side floods.
  • Manual URI block and allow wildcard rules now use stricter prefix-bound matching.
  • Verification infrastructure has additional edge-side throttling and caching for public verification assets.
  • Mitigation activation emails and Discord alerts are deduplicated more carefully to prevent duplicate notifications for the same incident.

Admin Operations

  • Admins can now update a user's email address and username from the Users area.
  • Account detail edits and password resets are now grouped into a clearer admin workflow.
19 June 2026

Dashboard and Traffic Visibility

  • The 30-day traffic chart now displays daily timeline labels instead of confusing time-of-day labels.
  • Monthly traffic views are now easier to read and load more efficiently on websites with larger histories.
  • Website traffic summaries remain aligned with the selected reporting period.

Website Management

  • Website SSL recovery tools are now available from the SSL area, making certificate troubleshooting easier to find.
  • Website deletion is now limited to admins to reduce the chance of accidental customer-side removal.
  • Website provisioning controls have been simplified so customers see fewer operational details.

Verification Reliability

  • Website verification settings are now applied more consistently across protected websites.
  • Verification behavior has been improved for customer websites that use protected paths or advanced verification.

Stability Improvements

  • Additional safeguards were added around invalid website host configuration.
  • Admin controls and website configuration flows now avoid more edge cases that could create confusing service warnings.
17 June 2026

Zero Trust Access

  • A new Zero Trust area is available for protecting private website paths.
  • Customers can add email-code access policies for sensitive paths such as admin panels, dashboards, staging areas, and internal tools.
  • Policy creation now uses a cleaner popup flow for adding or editing protected paths.
  • Access policies are managed individually, so each protected path can be active or paused on its own.
  • Email verification is now paired with an additional human check before an access code can be requested.
  • Access request screens no longer reveal whether an email address is allowed by a policy.
  • The Zero Trust interface has been simplified so customers focus on protected paths and policy status instead of global mode controls.
14 June 2026

Bandwidth Visibility

  • Website dashboards now show total traffic usage for the last 30 days.
  • Usage visibility includes both incoming and outgoing website traffic.
  • Live usage information has been added next to Traffic Health for quicker monitoring.
  • Application-level attack traffic that reaches the protected website is also included in usage visibility.
13 June 2026

Account Security Improvements

  • New registrations now require email verification before account access is completed.
  • Login protection has been improved for unusual sign-in activity.
  • If a login is detected from a new location, Shieldify can request an email verification code before allowing access.
  • Verification codes now have stricter safety limits to reduce abuse.
  • Password reset flows have been improved with clearer emails and a more polished reset experience.
  • Users can now enable authenticator app two-factor protection from the Profile page.
  • Authenticator setup supports both QR code scanning and manual setup codes.
  • When authenticator protection is enabled, sign-ins require an authenticator code after the password step.
  • Password changes for authenticator-protected accounts now require an authenticator code as an extra safety check.
  • For authenticator-protected accounts, unusual sign-in activity uses the authenticator app instead of email verification.

Email Notifications

  • Shieldify can now send important account, support, and protection notifications by email.
  • Support ticket updates can now reach users more reliably.
  • Attack start and end notifications can be delivered by email where enabled.
  • Website notification settings now include email controls and are easier to manage.

Better Traffic Visibility

  • Live traffic statistics are more accurate and less likely to show old data as current activity.
  • Traffic charts have been improved for websites with very low or no recent traffic.
  • Request counters and live views now recover more cleanly after configuration changes.
  • Admin traffic charts are easier to read and no longer show confusing axis values in some high-traffic cases.

Faster Request Log Experience

  • The Requests page has been optimized for websites with large traffic logs.
  • Searching request logs is now smoother and uses fewer resources.
  • Pagination now reports page counts more accurately.
  • Request classifications are displayed more clearly.

Website Access Management

  • The Access screen has been redesigned for clearer rule management.
  • Trusted IP and path rules are easier to add, review, and remove.
  • Unsafe broad allow rules are now rejected to help prevent accidental exposure.
  • Unsaved-change indicators are more accurate and no longer stay active when a rule list is returned to its original state.

SSL and Setup Flow Improvements

  • SSL controls now handle Force SSL more clearly.
  • SSL cannot be accidentally disabled while Force SSL is still active.
  • Website setup now supports custom origin ports for customers who do not use only the standard web ports.
  • Origin and SSL configuration feedback is clearer during setup and updates.

Admin and Website Management

  • Admins now have more control over whether members can create new websites.
  • Registrations can stay open while website creation remains admin-managed.
  • Admins can create websites on behalf of users from the admin panel.
  • User and website management screens have been refined for clearer daily operations.

Protection Reliability

  • Protection behavior has been tuned to better support legitimate high-volume customer traffic.
  • Trusted payment-related traffic handling has been improved.
  • Short-term abusive traffic handling is more controlled, helping reduce false positives while keeping active protection effective.