Security at Safezino
This page separates technical security, privacy commitments and anti-bypass product design. It does not claim a certification, external audit or absolute protection.
Verified technical properties
- The backend hashes account passwords with Argon2 before storage.
- The public web configuration sends an enforced Content Security Policy, HSTS, X-Content-Type-Options, Referrer-Policy and frame restrictions.
- Administrative routes are separated from public marketing routes and are excluded from search indexing.
- Blocklist rule packages are versioned and cryptographically signed in the checked-in pipeline.
Privacy properties
The privacy policy states that allowed browsing history is not collected. For a blocked gambling request, it states that the domain can be processed in memory and discarded while a count is retained.
Privacy commitments, retention periods, subprocessors and GDPR rights are described on the privacy pages. They are not security certifications.
Anti-bypass and product design
Safezino uses platform-specific filtering and a 24 to 72-hour deactivation delay to add friction during an urge. A trusted contact can be invited and must accept before receiving alerts. These are relapse-prevention design properties, not guarantees that bypass is impossible.
What we do not claim
- No claim of an external security audit.
- No claim of a security certification.
- No claim that every device configuration is impossible to bypass.
- No claim that Safezino replaces medical treatment or formal self-exclusion.
Report a vulnerability
Send a clear report to [email protected]. Include the affected component, reproduction steps and potential impact. Please avoid accessing other users’ data or disrupting the service while testing.