These are public summaries of policies maintained in full within SafeToOpen's ISO/IEC 27001:2022 certified ISMS. Full policies are available to customers under NDA via [email protected].
Information Security Policy (summary)
SafeToOpen maintains an information security management system (ISMS) certified to ISO/IEC 27001:2022, covering the development and operation of the SafeToOpen phishing-detection platform and services. Security objectives and risks are reviewed at least annually and on significant change, with executive ownership by the Managing Director. All personnel and contractors are bound by confidentiality obligations and complete security awareness training at onboarding and annually. Policies are reviewed at least annually; exceptions require documented risk acceptance by the Managing Director.
Access Control Policy (summary)
Access to SafeToOpen systems and customer data follows least privilege and role-based access control. Multi-factor authentication is required on all production, cloud, and code-repository access. Access is granted through a documented request and approval process, reviewed quarterly, and revoked within 24 hours of role change or departure. Administrative access to production is limited to named individuals and is logged. Shared accounts are prohibited; credentials are managed through a password manager with MFA.
Incident Response Policy (summary)
SafeToOpen maintains a documented incident response plan covering identification, containment, eradication, recovery, and post-incident review. Incidents are classified by severity with defined response targets per class (see the SLA & Support Policy). Customers affected by a confirmed data breach are notified without undue delay and no later than 72 hours after confirmation, including known impact, remediation steps, and a named contact — supporting customers' obligations under the NZ Privacy Act 2020, the Australian NDB scheme, and GDPR. The plan is exercised at least annually, and lessons learned feed policy and control updates.
Business Continuity & Disaster Recovery Policy (summary)
SafeToOpen services are hosted in New Zealand data centres operated by SiteHost. Backups are taken daily, encrypted, and restore-tested at least annually. Recovery objectives for core detection services are RTO 24 hours and RPO 24 hours. The browser extension fails safe: if the cloud service is unreachable, local protection continues and normal browsing is never blocked. The continuity plan covers loss of infrastructure, key personnel, and critical suppliers; vendor-continuity measures for customers (operational runbooks, contractual data return, and source code escrow as an enterprise contract option) are described in the Security Overview §9.
Vulnerability Management Policy (summary)
SafeToOpen identifies vulnerabilities through continuous automated dependency and infrastructure scanning, annual third-party penetration testing, and external researcher reports (see our Vulnerability Disclosure Policy). Remediation targets by severity: critical 48 hours, high 7 days, medium 30 days, low 90 days. Browser extensions additionally pass the independent review processes of the Chrome, Edge, and Firefox stores on every release.
Data Retention & Deletion Policy (summary)
SafeToOpen retains data only as long as needed for the purpose it was collected; per-category retention periods are published in the Data Handling & Privacy Statement §3. On contract termination, customer data is exported on request in a standard format and deleted within 30 days, with backup copies expiring within a further 35 days; confirmation of deletion is available on request. Individuals may request access, correction, or deletion of their personal information under the NZ Privacy Act 2020, GDPR, or other applicable law via [email protected].
Document control: v1.0 · These summaries are reviewed annually alongside their parent ISMS policies. Full policies under NDA: [email protected].