Administration console

HijackShield Console

The HijackShield Console is the administration console for HijackShield. Organizations use it to manage licenses, seats, and the devices enrolled under them. It performs no detection and receives no browsing data; the extension and agent do their work entirely on the device.

Administrators access the Console with the Microsoft or Google work account their organization already provides. There is no separate HijackShield account to create.

When you use your Google account, HijackShield receives your email address and name from Google and uses them only to identify you as an administrator of your organization. It requests nothing else from your Google account. Our privacy policy describes what we keep and for how long.

Console use is governed by our Privacy Policy and Terms of Service.

What you manage

Licenses, seats, and enrolled devices

Everything an administrator needs to keep a HijackShield deployment licensed and accounted for, in one place.

Licenses

See every HijackShield license issued to your organization, its tier, and the number of endpoints it covers. Activate new keys and retire old ones without touching individual machines.

Seats

Track how many seats are in use against your purchased capacity, so you can expand before a new device is turned away at enrollment.

Enrolled devices

Every device running the HijackShield Agent registers against a seat. Review what is enrolled, and revoke devices that have left your fleet to free their seats.

Google and Microsoft account data

Your work account, and nothing more

Administrators access the Console with their organization's Microsoft Entra ID or Google Workspace account, using OpenID Connect. We request only the standard openid, email and profile scopes — enough to confirm who you are and connect you to your organization's Console records.

We never request access to your mailbox, files, calendar, contacts, or any other data held by Google or Microsoft. Section 2 of the Privacy Policy describes exactly what we receive from your account provider, how we protect it, and how long we keep it.

Received from Google or Microsoft

  • Your email address and display name
  • The provider's subject identifier for your account
  • Your organization's tenant identifier and the token issuer

Never requested

  • Mailbox, files, or calendar access
  • Contacts or directory data
  • Any scope beyond the three OpenID Connect basics
Where the Console sits

Management only. Never detection.

Detection and scoring run entirely on the user's device. The Console performs no detection and no scoring, and no page content, URLs, browsing history, form inputs, or detection results are ever transmitted to it.

The browser extension does not communicate with the Console at all — it talks only to the HijackShield Agent on the same machine over the loopback interface. The one component that does contact the Console is the Agent, and only to validate a license and register the device against a seat.

From
To
What travels
Browser extension
HijackShield Agent, same machine (127.0.0.1)
Page signals for detection and scoring. The loopback interface is not network-routable, so this data cannot leave the device.
HijackShield Agent
HijackShield Console
The license key, a locally generated device identifier, and the Agent's version number — at deployment and once at each startup. Nothing else, ever.
HijackShield Agent
Your organization's Azure tenant (optional)
Detection events to your own Microsoft Sentinel workspace, if you configure the integration. This traffic does not pass through AiTM Security.

Policies that cover the Console

Both documents apply to the HijackShield Console, the HijackShield Agent, and the browser extension, and describe what each one does and does not collect.

Manage your HijackShield deployment

Deploy HijackShield to your organization, or talk to us about licensing and seats.