SafeToNet Ltd
HarmBlock and HarmBlock-derived technology
Behind every deployment of HarmBlock is a child we are trying to protect.
That is the whole of it, really. Behind every install figure and every integration is a real child and a concerned parent about their child’s real world and online world protection. It is why we build what we build, and it is why we have written this policy as parents, grandparents, uncles, aunts and those that had too little protection when we ourselves were too young.
We are trying to do something that has not been done before: make devices safe by the way they are made, rather than by watching children after the fact. Nobody has built this before us, which means the more people involved in supporting its development is appreciated. We would very much rather find that out from you as early as possible.
So: if you have found something, please tell us. We will be glad you did, even on the days when it stings.
HarmBlock is a component, an on-device and app safeguarding AI. It isn't something you can buy on its own. If it’s on a device or embedded within an app, it provides private, real-time protection for children’s digital worlds.
Manufacturers and developers then build it into their own devices, operating systems and apps. It is deployed through environments we do not build, do not host and cannot see into.
Some findings will arise from HarmBlock itself and can be fixed directly by SafeToNet. Others will arise from the way HarmBlock has been integrated into a partner’s device, application or service and will require that partner to make the change. In either case, please report it.
We say this so you know where a fix will have to come from. We do not say it to send you away. If what you have found sits with a partner rather than with us, we will find the right person, hand it over with your permission, and we will remain engaged with the report and the relevant partner while it is investigated and addressed.
So please, when in doubt, please still send it to us.
Going straight to them is usually fastest. Coming to us is always welcome.
Tell us what you found and how to see it for ourselves: the device, the versions, the steps. Tell us how you'd like to be contacted.
One request, and we hope an obvious one: never send us real images of a person, and never anything involving a child. Describe it instead. If you think you need imagery to prove the point, say so as long as it is a legal image we will work out a safe way together. If it is an illegal image we will bring in one of our partners that handles this type of material. We cannot see it or receive it.
We reply and ask if you are happy for us to pass on your data to a third party and support you if needed.
We believe in coordinated vulnerability disclosure. We aim to acknowledge reports within five business days and will work to investigate and remediate confirmed issues within an appropriate timeframe. We will not unreasonably seek to prevent a researcher from publishing their findings following reasonable coordination with us. Where we have legal or regulatory obligations to notify regulators, customers or affected individuals, we will meet those obligations independently of the vulnerability disclosure process.
Where real people are at real risk, we will tell them. We will not use a disclosure window to keep parents in the dark about something they need to know in order to protect their child. That would make us the problem we exist to solve.
If you act in good faith under this policy, we will always respond to you, be proactive and be as helpful as we can. We will not support anyone who breaches our policy and seeks to undermine our mission to safeguard children.
Good faith means the ordinary things: don't destroy data, don't disrupt the service, look at only as much as you need to prove the point, don't keep or share what you find, and do not attempt to undermine a child we protect or place any children we protect at risk.
We can only speak for ourselves. This protection cannot cover our manufacturing partners. If your work takes you into their platforms, check their policy too, and tell us, so we can make the introduction.
We know that reporting a flaw in a child-safety product is an uncomfortable thing to do. You may worry you'll be shouted at, or sued, or quietly ignored. We are asking you to trust us instead, and we understand that trust has to be earned rather than requested.
So here is where we stand. We do not measure ourselves by devices shipped or contracts signed. We measure ourselves by children who were protected by the image that was never taken, the moment that never became a memory, the parent who never got the phone call. Every flaw you find and we fix moves that number in the right direction.
That makes you part of this, not a threat to it. Finding a weakness in this technology is a contribution to it. Please come to us first, and we will try very hard to be the kind of company you're glad you came to.