Security you can inspect.
We would rather show you the architecture than ask for blind trust. Here is exactly how Koru Shield protects your traffic, and where we are still improving.
Encrypted DNS only, by design
Every Koru Shield lookup travels over DNS-over-HTTPS (DoH). Plain, unencrypted DNS on port 53 is refused entirely. Unencrypted lookups can be observed and tampered with on the network, so we do not offer a downgrade path, even a convenient one.
Unknown devices get refused, not waved through
Our resolvers answer only for linked clients. Anything else receives an explicit refusal. There is no open resolver here, and strangers cannot use our infrastructure to bounce traffic.
US-first infrastructure
Koru Shield runs on servers in the United States, with us.korushield.com routing you automatically to the fastest location. Your DNS data stays in the United States. We are expanding regions after launch, and we will say exactly where your data lives as we do.
Private by design
We never sell your data, and we never will. We collect the minimum needed to run the service: your account details, the domain names you look up (which is how filtering works), and your profiles. We do not see the content of your browsing, your messages, or anything inside encrypted connections. Full details are in the privacy policy.
Honest blocking, no silent failures
When Koru Shield stops something, you see a clear page explaining what was blocked and why, with a way to allow it if you choose. And unlike some free DNS tiers, we never silently switch you to unfiltered resolving. If protection ever cannot apply, we tell you.
Where we are still improving. An independent privacy and security audit is planned, and we will publish the full report when it is done. Until then, we will not claim certifications we do not have. If you find a vulnerability, email contact@korushield.com and we will respond promptly.
Protection with nothing to hide.
Get started and get encrypted, honest DNS filtering free.