How FNS Shield works.
Written plainly enough for anyone, but with enough technical detail that a security-minded reader can trust it.
This page covers the browser extension specifically — one part of the FastTech Shield service, and the part with the most moving pieces. The rest of the service (the bench setup, the filtered connection, the remote-access cleanup, the number on your monitor) is described on the overview. The extension is live in the Chrome Web Store today, and the separate Windows desktop program shipped too — see below for that, and see status for where Edge stands.
The four things it watches for
Every page you visit is checked against four independent detection rules. If any one fires, a full-width warning card appears at the top of the page — you have to see it before you can interact with what’s below.
1. Fake tech-support numbers
Pages that combine a prominent 1-800 number with scare language and unauthorized Microsoft, Apple, or Google branding. Requires the impersonated brand to appear in a heading, title, or logo — not just in prose — to keep precision high.
2. Browser lockers
Pages that force your browser into full-screen, hide the close controls, or spawn dialog loops (“are you sure”, “stay on page”). Real websites do not do this.
3. Remote-access tool downloads
If a page offers AnyDesk, TeamViewer, UltraViewer, Supremo, RustDesk, Ammyy, or Quick Assist from anywhere except the real vendor’s domain, we warn. Scammers typically host these on look-alike domains.
4. ClickFix / paste-into-PowerShell
The newest scam wave. Pages tell you to press Windows+R, open PowerShell, and paste a command. We detect the instruction language and PowerShell syntax markers before flagging.
On top of the four rules, we ship a signed bad-domain blocklist that updates every six hours from our CDN. If the current page’s hostname is on the list, the warning fires before we even run the heuristics.
The warning overlay is built to resist the page
The warning card is rendered into a closed shadow DOM attached to the root of the page. That’s a technical way of saying the page’s own JavaScript cannot read or restyle the inside of the card. If the page deletes the card’s container outright, we detect that and put it back. Keyboard dismissal only responds to a real keypress from you — a keystroke faked by the page is ignored. This matters because real scam pages actively try to suppress warnings.
We won’t tell you it cannot be bypassed. Anything running on the page can keep trying, and a determined scam page can still contest what sits on top. What we can say is that each of those attempts has to beat a specific defence, and that we treat any way around them as a bug worth fixing fast.
The license lives on your device
Your plan carries an Ed25519-signed license. A FastTech technician normally activates your license on the bench before your machine goes home, so there is nothing for you to do. If you ever need to turn it on yourself — a second computer, a browser reinstall — you will open the extension, type the email address we have on file, and click the sign-in link we send you. Protection turns on by itself once you click that link. There is no key to type or paste — just that email address; if you check the popup before you finish, it will say “Not set up yet” and mention a “licence key” — tapping Activate there just takes you back to that same sign-in link, not a key to hunt down.
Once activated, the extension verifies that license offline against a public key baked into the extension. It does not check in with a server to decide whether you’re allowed to be protected, and there is no phone-home for authentication.
If we ever need to revoke a specific license (you cancel, or a machine leaves the plan), your extension picks up the change on its next 6-hour refresh via a signed revocation list on our CDN.
What we do not collect
Not collected
The URLs you visit · the content of pages · your search history · usernames or passwords · what websites you go to · anything about your bank, email, or accounts.
What is stored
The email address on your account · your Square customer and payment IDs · which plan and how many seats you have · when a license was issued, renewed, or revoked. See the Privacy Notice for the full list.
It runs alongside your antivirus
FNS Shield is a browser extension. It complements Windows Security, Malwarebytes, Norton, McAfee, or whatever else you already use. It does not compete for the same job — antivirus scans files, we watch web pages. Both matter.
Live on Chrome now. Edge, Firefox, and Safari later.
The extension is built for Manifest V3 and targets Chrome 120+. It is live in the Chrome Web Store and included with every plan — add it to Chrome, or bring the computer in and we will set it up. That listing is unlisted, so it will not turn up if you search the Chrome Web Store — the link above is the way in. See the status page for where things stand for Edge, Firefox, and Safari.
There is no macOS app. A separate Windows program watches for remote-access tools like AnyDesk and TeamViewer — it is not a browser extension and is not covered by this page. It shipped on 2026-08-25 as a signed installer and is included with Shield Complete — installed at your bench visit, and it checks for updates itself afterward. See the overview for where that stands.
Included with every plan · cancel any time by calling or stopping in.