Security at Safezino

This page separates technical security, privacy commitments and anti-bypass product design. It does not claim a certification, external audit or absolute protection.

Verified technical properties

  • The backend hashes account passwords with Argon2 before storage.
  • The public web configuration sends an enforced Content Security Policy, HSTS, X-Content-Type-Options, Referrer-Policy and frame restrictions.
  • Administrative routes are separated from public marketing routes and are excluded from search indexing.
  • Blocklist rule packages are versioned and cryptographically signed in the checked-in pipeline.

Privacy properties

The privacy policy states that allowed browsing history is not collected. For a blocked gambling request, it states that the domain can be processed in memory and discarded while a count is retained.

Privacy commitments, retention periods, subprocessors and GDPR rights are described on the privacy pages. They are not security certifications.

Anti-bypass and product design

Safezino uses platform-specific filtering and a 24 to 72-hour deactivation delay to add friction during an urge. A trusted contact can be invited and must accept before receiving alerts. These are relapse-prevention design properties, not guarantees that bypass is impossible.

What we do not claim

  • No claim of an external security audit.
  • No claim of a security certification.
  • No claim that every device configuration is impossible to bypass.
  • No claim that Safezino replaces medical treatment or formal self-exclusion.

Report a vulnerability

Send a clear report to [email protected]. Include the affected component, reproduction steps and potential impact. Please avoid accessing other users’ data or disrupting the service while testing.