SafeToOpen protects people from phishing by analyzing the web pages they visit — so we hold ourselves to a higher standard on what we do with that access. Everything on this page is documented, certified, and available for your security team to verify.
Our information security management system is independently certified. Certificate available on request while we finalise publishing it here.
Performed by an independent security firm; the summary letter is available under NDA.
Every extension release is independently reviewed by the Chrome, Edge and Firefox stores before it reaches you.
Certificate of currency available on request.
Architecture, encryption, access control, monitoring and continuity — the full picture for security reviewers.
Read →PoliciesInformation security, access control, incident response, BC/DR, vulnerability management and retention.
Read →PolicyFound something? How to report it, what we commit to, and safe harbor for good-faith research. Also at /.well-known/security.txt.
Exactly what our products see, what leaves your browser, what we store — and for how long.
Read →StatementOur models, our training data, and our commitment that customer data is never used to train them.
Read →RegisterEvery third party we use to deliver the service, what each processes, where, and under which safeguards.
Read →“History checks use one-way hashes of URLs — your actual browsing is never exposed, never sold, never used for ads.” Related: Privacy Policy · Data Processing Agreement · Our Privacy Promise
99.5% uptime target, defined support severities and response times, and service credits.
Read →Local protection in your browser keeps working and browsing is never blocked. An outage at our end never locks you out of the web.
Documented operational runbooks, contractual data return on exit, and source code escrow available as an enterprise contract option.
Legal: Terms of Service · DPA
Under NDA we provide our ISO 27001 Statement of Applicability and latest audit summary, penetration test summary letter, completed CAIQ questionnaire, full security policies, insurance certificate of currency, and our continuity plan.
Typical turnaround: one business day.
Analysis runs in the browser first; a page’s visual elements and URL are sent to our cloud only when the page can’t be cleared locally. Business customers can exclude internal domains entirely, so internal applications are never submitted. Form values, passwords, keystrokes, and files are never transmitted.
No. Our models are trained on phishing and legitimate pages we gather ourselves and on confirmed threat intelligence — never on customer data.
In New Zealand, in data centres operated by SiteHost. New Zealand holds a European Commission adequacy decision for data protection.
The extension fails safe: local protection keeps working and browsing is never blocked. Our SLA targets 99.5% monthly uptime with service credits.
We document the answer rather than dodge the question: operational runbooks a third party could run the service from, contractual data return on exit, and source code escrow available in enterprise agreements.
Security: [email protected] · Privacy: [email protected] · General: [email protected]
Page last reviewed: July 2026