Security and privacy you can verify.

SafeToOpen protects people from phishing by analyzing the web pages they visit — so we hold ourselves to a higher standard on what we do with that access. Everything on this page is documented, certified, and available for your security team to verify.

ISO/IEC 27001:2022 Certified GDPR Compliant NZ Privacy Act 2020 Independently Pen-Tested Data Hosted in New Zealand

Certifications & assurance

Certified

ISO/IEC 27001:2022

Our information security management system is independently certified. Certificate available on request while we finalise publishing it here.

Tested

Independent penetration testing

Performed by an independent security firm; the summary letter is available under NDA.

Reviewed

Browser store review

Every extension release is independently reviewed by the Chrome, Edge and Firefox stores before it reaches you.

Insured

Cyber liability insurance

Certificate of currency available on request.

Security

Privacy & data handling

“History checks use one-way hashes of URLs — your actual browsing is never exposed, never sold, never used for ads.” Related: Privacy Policy · Data Processing Agreement · Our Privacy Promise

Reliability & continuity

Policy

SLA & Support

99.5% uptime target, defined support severities and response times, and service credits.

Read →
Fail-safe

If our cloud is unreachable

Local protection in your browser keeps working and browsing is never blocked. An outage at our end never locks you out of the web.

Continuity

Vendor continuity

Documented operational runbooks, contractual data return on exit, and source code escrow available as an enterprise contract option.

Legal: Terms of Service · DPA

Doing due diligence on SafeToOpen? We’ll make it easy.

Under NDA we provide our ISO 27001 Statement of Applicability and latest audit summary, penetration test summary letter, completed CAIQ questionnaire, full security policies, insurance certificate of currency, and our continuity plan.

Typical turnaround: one business day.

Questions security teams ask us

Analysis runs in the browser first; a page’s visual elements and URL are sent to our cloud only when the page can’t be cleared locally. Business customers can exclude internal domains entirely, so internal applications are never submitted. Form values, passwords, keystrokes, and files are never transmitted.

No. Our models are trained on phishing and legitimate pages we gather ourselves and on confirmed threat intelligence — never on customer data.

In New Zealand, in data centres operated by SiteHost. New Zealand holds a European Commission adequacy decision for data protection.

The extension fails safe: local protection keeps working and browsing is never blocked. Our SLA targets 99.5% monthly uptime with service credits.

We document the answer rather than dodge the question: operational runbooks a third party could run the service from, contractual data return on exit, and source code escrow available in enterprise agreements.

Security: [email protected] · Privacy: [email protected] · General: [email protected]
Page last reviewed: July 2026