Security & Encryption
Your safety and privacy are our top priorities. Learn about the enterprise-grade security measures that protect your emergency communications.
Security Features
Enterprise-grade security measures protecting your most sensitive information
Strong Encryption
Emergency messages and files are encrypted with AES-256. Each package uses a fresh content key, wrapped individually for every authorized contact.
Secure Infrastructure
Built on enterprise-grade cloud infrastructure whose data centers hold SOC 2 certification, with 24/7 automated monitoring.
One-Time Password Authentication
Secure, passwordless access using one-time codes sent directly to your email. No passwords to remember or leak.
Per-Contact Key Wrapping
Every emergency package is encrypted for specific recipients using RSA-2048 public keys. A contact's private key is itself stored encrypted, protected by their PIN.
PIN-Protected Access
Only contacts holding the correct PIN can unlock emergency data. PINs are stored as cryptographic hashes only, with rate limiting against brute force and no PIN recovery.
GDPR Compliant
Full compliance with GDPR, CCPA, and other international privacy regulations.
Encryption Standards
Data in Transit
All communications between your device and our servers use the latest TLS encryption standards with perfect forward secrecy. This ensures that even if encryption keys are compromised in the future, past communications remain secure. Every API call, file upload, and data sync is protected during transmission.
Data at Rest
Emergency messages and files are encrypted with AES-256-GCM before being stored. Each package uses a fresh content key, wrapped for each authorized contact with RSA-2048. A contact's private key is itself stored encrypted, protected by a key derived from their PIN using industry-standard key derivation. PINs are stored only as cryptographic hashes: if a PIN is lost, we cannot restore access to data already encrypted for it.
Key Management
Contact keypairs are generated in the contact's browser when they accept their role, and the private key is stored only in encrypted, PIN-protected form. Recipients decrypt emergency messages and links directly in their browser. Server-side data encryption (for non-sensitive metadata like timestamps and status) uses built-in encryption with regularly rotated keys managed through industry-standard practices.
Infrastructure Security
Data Centers
Safety Checkpoint is built on enterprise-grade cloud infrastructure with SOC 2 Type II certified data centers featuring 24/7 physical security, redundant power systems, and environmental monitoring. Data is replicated across multiple availability zones for high availability and disaster recovery.
Network Security
Multi-layered network security including DDoS protection at our hosting providers' edge networks, infrastructure-level protections from our certified providers, and rate limiting on all sensitive API endpoints. All database connections use encrypted protocols.
Monitoring & Logging
Comprehensive security event logging tracks authentication attempts, PIN verification, emergency protocol triggers, and data access patterns. Real-time monitoring with automated alerts for suspicious activity. All logs are encrypted and retained for 90+ days for security analysis and compliance.
Access Controls
Employee Access
Strict principle of least privilege with role-based access controls. Administrative access to production systems is limited to essential personnel only. All privileged actions are logged and reviewed. Multi-factor authentication is required for all administrative access to infrastructure.
Customer Data
Emergency content is stored encrypted and is unlocked by contact PINs, which we store only as cryptographic hashes and cannot recover for you. Day-to-day operation relies on non-sensitive metadata (protocol status, timestamps). Every access to emergency data requires PIN verification, is rate limited, and is logged.
Audit Trails
Comprehensive audit logging of all authentication events, PIN attempts, emergency access, protocol triggers, and administrative actions. Secure audit log storage with tamper-resistant controls. Security events are retained for 90+ days and can be exported for compliance purposes.
Compliance & Architecture
The regulations we follow, the architecture we chose, and what our providers certify
SOC 2 Type II Infrastructure
Our infrastructure providers hold SOC 2 Type II certification. That covers the platforms and data centers we build on, not an audit of Safety Checkpoint itself.
GDPR Compliant
Full compliance with European data protection regulations including right to access, rectification, and deletion
CCPA Compliant
California Consumer Privacy Act compliance with transparent data practices and user rights
Envelope Encryption Architecture
Emergency content is stored encrypted, and the keys that unlock it are protected by contact PINs stored only as cryptographic hashes. We do not offer PIN recovery.
Our Security Practices
Continuous security improvement through industry best practices
Regular Security Audits
Security-focused development practices with thorough code review for critical features including authentication, encryption, and data access controls. Static analysis with SonarQube and automated dependency scanning with Snyk, patched as advisories land. An automated security test suite runs in CI on every change. Community-driven security through responsible disclosure.
Vulnerability Management
Continuous dependency monitoring with automated updates for security patches. Proactive vulnerability scanning and immediate response to security advisories. All security updates are tested in staging environments before production deployment to ensure stability.
Incident Response
Automated monitoring raises admin alerts on suspicious activity, elevated error rates and delivery failures. If an incident ever affects your data, we notify you directly and publish what happened in the changelog. We report personal data breaches to the competent supervisory authority within 72 hours, as GDPR requires.
Report a Security Vulnerability
We take security seriously. If you've discovered a vulnerability, please report it responsibly.
Our Commitment
• Recognition: While we don't offer a formal bug bounty program, we deeply appreciate security researchers and will provide recognition based on the significance of your discovery.
• Responsible Disclosure: Please allow us reasonable time to address vulnerabilities before public disclosure.
• No Legal Action: We will not pursue legal action against researchers who follow responsible disclosure practices.
Contact Methods
Email: legal@safety-checkpoint.com
PGP Key: Request our PGP public key at legal@safety-checkpoint.com
Submit Vulnerability Report
Please provide detailed information to help us understand and address the issue quickly.
