HijackShield Console
The HijackShield Console is the administration console for HijackShield. Organizations use it to manage licenses, seats, and the devices enrolled under them. It performs no detection and receives no browsing data; the extension and agent do their work entirely on the device.
Administrators access the Console with the Microsoft or Google work account their organization already provides. There is no separate HijackShield account to create.
When you use your Google account, HijackShield receives your email address and name from Google and uses them only to identify you as an administrator of your organization. It requests nothing else from your Google account. Our privacy policy describes what we keep and for how long.
Console use is governed by our Privacy Policy and Terms of Service.
Licenses, seats, and enrolled devices
Everything an administrator needs to keep a HijackShield deployment licensed and accounted for, in one place.
Licenses
See every HijackShield license issued to your organization, its tier, and the number of endpoints it covers. Activate new keys and retire old ones without touching individual machines.
Seats
Track how many seats are in use against your purchased capacity, so you can expand before a new device is turned away at enrollment.
Enrolled devices
Every device running the HijackShield Agent registers against a seat. Review what is enrolled, and revoke devices that have left your fleet to free their seats.
Your work account, and nothing more
Administrators access the Console with their organization's Microsoft Entra ID or Google Workspace account, using OpenID Connect. We request only the standard openid, email and profile scopes — enough to confirm who you are and connect you to your organization's Console records.
We never request access to your mailbox, files, calendar, contacts, or any other data held by Google or Microsoft. Section 2 of the Privacy Policy describes exactly what we receive from your account provider, how we protect it, and how long we keep it.
Received from Google or Microsoft
- Your email address and display name
- The provider's subject identifier for your account
- Your organization's tenant identifier and the token issuer
Never requested
- Mailbox, files, or calendar access
- Contacts or directory data
- Any scope beyond the three OpenID Connect basics
Management only. Never detection.
Detection and scoring run entirely on the user's device. The Console performs no detection and no scoring, and no page content, URLs, browsing history, form inputs, or detection results are ever transmitted to it.
The browser extension does not communicate with the Console at all — it talks only to the HijackShield Agent on the same machine over the loopback interface. The one component that does contact the Console is the Agent, and only to validate a license and register the device against a seat.
Policies that cover the Console
Both documents apply to the HijackShield Console, the HijackShield Agent, and the browser extension, and describe what each one does and does not collect.
Manage your HijackShield deployment
Deploy HijackShield to your organization, or talk to us about licensing and seats.