← Trust Center
Statement

AI & Machine Learning Transparency Statement

How SafeToOpen uses machine learning to detect zero-day phishing — our models, our data, and our commitment that customer data is never used for training.

Audience: Security, privacy, and legal reviewers · Classification: Public · Version: 1.0 — July 2026

Why we use AI

Traditional phishing defences rely on blocklists, which only protect against threats someone has already reported. SafeToOpen uses machine learning to detect zero-day phishing pages — pages no one has seen before — in real time, compressing detection from hours or days to seconds.

Our models

SafeToOpen operates two complementary detection engines. X-Ray inspects the underlying code and structure of a page to identify threats invisible to the human eye; it runs locally in the user's browser. VisionAI analyzes a page the way a person sees it — logos, branding, layout, and login forms — to detect visual impersonation of trusted brands; it runs in the SafeToOpen cloud and receives a page's visual elements and URL only when the page cannot be cleared locally. A page is judged on the combination of signals.

What data the models process

The models analyze web page content and structure (and, for the Email Verification products, customer-reported emails) for the sole purpose of threat detection. Exactly what data is accessed, what leaves the browser, and how long it is retained is set out in the SafeToOpen Data Handling & Privacy Statement. Model inputs are never used for advertising, profiling, or sale.

Training data

Our models are trained on data we gather ourselves: publicly reachable phishing and legitimate web pages collected by our own systems, and confirmed threat intelligence. Customer data is not used to train or improve our models. No third-party AI service processes customer data on our behalf; any change to this position would appear on our Sub-Processor List with 30 days' notice before taking effect.

Human oversight

Machine verdicts are backed by human review: customer-reported false positives are reviewed by a person, and model updates are tested against regression suites of known-good and known-malicious pages before release. Model changes follow the same controlled release process as all SafeToOpen software.

Accuracy, false positives and user control

No detection system is perfect. When SafeToOpen blocks a page, the user is shown the reason, and users and administrators can report a false positive directly from the product or via [email protected]. Reported false positives from business customers are treated with high priority (see the SLA & Support Policy), and corrections propagate automatically to all users. Business customers can have internal domains excluded from analysis entirely.

Governance

AI development at SafeToOpen sits inside our ISO/IEC 27001:2022 certified ISMS: model changes follow our secure development and release process, access to training data and model infrastructure is role-restricted, and this statement is reviewed annually. We are tracking ISO/IEC 42001 (AI management systems) and reviewing our alignment with it as the standard's adoption matures.

Questions

AI or privacy questions: [email protected] · General: [email protected]

Document control: v1.0 · Approved by the Managing Director · Next review: July 2027. Related: Data Handling & Privacy Statement · Security Overview · Privacy Policy · DPA.

Questions from your security team?

We answer reviewer questions directly and provide the full security review pack under NDA — typical turnaround one business day.

Contact [email protected]