About CyberShield Studio
Built by people who ran PCI at scale, for stores that never will.
We watch storefronts and checkouts for SME ecommerce merchants — what runs on your store, where customer data goes, and whether your shopper still reaches the payment page you chose. When something has already landed with a deadline on it, we also take bounded engagements to fix it.
The people who read your alerts
Security and PCI here are led by two people. On a paid plan, one of them has looked at a finding before it reaches you — which is the part of this product that automation cannot supply, and the reason their record is on this page at all.
Dennis Wu
Founder · leads security and PCI · CISSP, PCIP
Thirty years building and securing large-scale payment platforms. As CTO at buuteeq and Head of Engineering at Booking.com's BookingSuite he led PCI Level 1 compliance programs — re-architecting network segmentation to shrink cardholder-data scope, and running enterprise vulnerability management. As acting CSO at Linc he owned security governance for retail brands including PacSun, Carter's and Levi's.
He is also a working AI builder — Chief AI Architect at E2 Nova, previously co-founder and CTO of Linc — with an MS in Computer Science from Stanford. That pairing is the reason the engine and the review step are designed by the same person: knowing what an agent can be trusted to decide, and what it cannot, is the whole design problem here.
Brandon Wu
Security analyst · Security+, BSCP
A BS in Cybersecurity, CompTIA Security+, and Burp Suite Certified Practitioner — hands-on testing of web applications for weaknesses in authentication, access control, session handling and application logic. He runs the day-to-day review: reading what each scan found, separating the changes that matter from the forty that do not, and staying with an issue through to the run that confirms it is fixed.
Credentials & education
CISSP
Certified Information Systems Security Professional
PCIP
PCI Professional
Security+ · BSCP
CompTIA · Burp Suite Certified Practitioner
MS, Stanford
Computer Science
What we do with what we see
We are asking to look closely at a store that is not ours. Here is how we handle that.
We watch from outside, and install nothing
No script on your pages, no plugin, no code change. We read your store the way anyone else pointing a browser at it would — which also means we never become one more third party on the page that takes card details.
We ask before we do anything active
Monitoring starts only after you prove the domain is yours. That verification is also what lets us answer your consent banner and walk your checkout — neither of which we will do on a store that has not asked us to. We never ask for card data, and we never handle it.
We say which kind of answer you got
AI does the legwork — every script, every request, every consent signal, compared against last week. A person decides which of those changes is worth your attention. We tell you which of the two produced a finding, rather than presenting automation as judgement.
And what we will not tell you
We do not sell fear. We publish our method, we never quote statutory damages at you, and when something we found probably does not matter we say so — including when a claim against you looks weak. That last one costs us work, and it is the reason to believe the rest.
We monitor and report. We do not block attacks, and we do not certify compliance. We are not a QSA or an ASV, and nothing we run satisfies PCI DSS Requirement 11.3.2. Your self-assessment, risk decisions and attestation remain your own — we make sure you are not making them blind.
Get in touch
Questions about the platform, an engagement, a partnership or press — we read everything. If you are holding a notice with a date on it, start with triage instead; it gets you an answer faster.