Security
Security you can audit, not adjectives
No “bank-level security” here. This page lists the actual mechanisms protecting your family's data — written by the engineers who built them, including what we haven't built yet.
Child's device
Collects location & screen-time totals
only after visible consent
Encrypted in transit
All traffic uses HTTPS/TLS
nothing travels in plain text
Safentora API
Processes data to power safe-zone alerts*
credentials stored only as hashes
Your family only
Visible to guardians in your family group
never advertisers or brokers
The mechanisms
How your family's data is protected
Each card starts in plain language. Expand “under the hood” for the exact technical detail.
Passwords are never stored
We store a one-way scrambled version of your password. Even if someone stole our database, your actual password isn't in it.
Under the hood
Sessions expire in minutes, not months
The credential your device actually uses is replaced every few minutes. A leaked one goes stale almost immediately.
Under the hood
A stolen session locks itself out
Session credentials rotate on every renewal. If an old one is ever replayed — the signature of theft — every session on the account is revoked instantly.
Under the hood
The browser never holds long-lived credentials
On the web dashboard, your session lives in a sealed cookie that page scripts cannot read — so even a malicious script couldn't steal it.
Under the hood
Admin and family access can't cross wires
Platform-administration access is a separate system from family accounts — an admin credential is structurally useless on family data routes, and vice versa.
Under the hood
Child devices pair with a one-time code
You create your child's account, then connect their phone with a short-lived pairing code you generate. Each code works once and expires after 10 minutes.
Under the hood
Brute force hits a wall
Repeated login or pairing attempts from one source are cut off quickly.
Under the hood
Least privilege on the child's device
The powerful device permissions we use are scoped to the minimum: remote lock can lock the screen — and nothing else.
Under the hood
Honest limits
What we haven't built yet
Admitting gaps beats hiding them. This roadmap is public on purpose — hold us to it.
- Two-factor authentication for guardian accountsplanned
- Encryption at rest for the location databaseplanned
- Independent third-party security auditplanned
- Published transparency reports on a fixed cadenceplanned
Work with us
Found something? Tell us.
Good-faith security research helps every family using Safentora. We won't pursue action against researchers who report responsibly.
Report a vulnerability
Describe the issue, how to reproduce it, and its impact. Please don't access other families' data while demonstrating it.
security@scientistshublabs.dev
We acknowledge reports within 72 hours.
Report a security incident
Think your family's account was compromised? Contact us and revoke sessions from your dashboard — one password change signs out every device.
security@scientistshublabs.dev
Incident reports are prioritized same-day.
Want the everyday-language version? Read the privacy policy or visit the Trust Center.