SafeToOpen
SafeToOpen Documentation
Deployment, policy and integration guides for Browser Security and Email Security, and how-to guides for Scam Check, for administrators and MSPs.
Deployment Guides
Install and register SafeToOpen Browser Security on every platform, device and browser your organisation uses, with nothing for the user to do.
Overview and Enrolment Key
How install and registration work, the four policy values, the enrolment key, workspaces, verification. Start here.
Windows: Edge and Chrome with Intune
Force-install through the Settings Catalog and push the enrolment values with a platform script. Zero user action.
Windows: Group Policy and registry
On-premises AD, RMM tools or hand-built images: ADMX templates, a .reg file and a logon script.
macOS: Chrome, Edge and Safari
Managed preferences via Intune or Jamf, a root script for per-user values, and Safari through the Mac app plus DDM.
iPhone and iPad: Safari
Apple Business Manager, Intune VPP, app configuration for the enrolment values, and Safari extension DDM.
Chrome Enterprise (Google Admin)
Chrome Browser Cloud Management and ChromeOS: force-install and the extension policy JSON from the Admin console.
Android, unmanaged devices and activation emails
Where no policy channel exists: Edge on Android, BYOD, contractors, and the activation-email and Azure AD routes.
Apple MDMs: Jamf, Kandji, Mosyle, Addigy, SimpleMDM
The same profile, script and app-configuration payloads in each Apple MDM, with the menu paths and variables each one offers.
Windows RMM and UEM tools
NinjaOne, Datto RMM, ConnectWise, Kaseya, Atera, Action1, PDQ, ManageEngine, MECM and Workspace ONE: where to run the script or push the registry.
Linux: Chrome and Edge
JSON policy files under /etc, delivered by Ansible, Puppet, Landscape or any package: force-install and the enrolment values.
Cross-platform UEMs: ManageEngine MDM Plus, SOTI MobiControl, Hexnode
One console for Windows, macOS, iOS and Android: where each of the three puts scripts, custom profiles, app configuration and Android app push.
Ticketing, SIEM & Threat Feed Integration Guides
Send Browser Security incidents to ServiceNow, Jira, your SIEM or SOAR, close the loop, and bring your own threat intelligence in.
Overview and Setup
Concepts, choosing push, pull or email-to-ticket, and step-by-step console setup. Start here.
ServiceNow Integration Guide
Scripted REST receiver, incident mapping, close-the-loop Business Rule and a polling alternative.
Jira Integration Guide
Jira Automation incoming webhook or a signature-verifying relay, plus close-the-loop rules.
Webhook and API Reference
Payloads, headers, signature verification code, polling, schema variants and error codes.
Threat Feeds: Bring Your Own Intelligence
Ingest vendor or community URL feeds on a schedule so their entries are blocked in every workspace. Presets, formats, TAXII and MISP, caps and removal.
Response Actions: Blocklist, Microsoft 365, Entra ID, Defender, Okta, EDR, Web Gateways, Paging, Chat and MSP Propagation
What each integration lets you do, with a capability table across all 24 connectors, then per integration: what you need, the vendor-side and console set-up step by step, the actions with their scope and undo, and the rules to write.
MSP Operations: Overview, Linked Organisations and Administrator Access
One screen across every organisation you administer, MSP-wide blocking through linked organisations, co-admins that follow an identity-provider group, and required SSO for administrators.
Email Security Deployment Guides
Roll out SafeToOpen Email Security to Outlook and Gmail across an organisation, license every mailbox without activation links, and run it from the Business Console.
Overview: how Email Security is deployed and licensed
Add-ins, seats, how a mailbox becomes a licensed member with no activation link, workspaces, and what the console controls. Start here.
Outlook: Microsoft 365 deployment
Integrated apps from AppSource or the branded manifest per workspace, group import from Entra ID, multi-tenant for MSPs, verification.
Gmail: Google Workspace deployment
Marketplace domain install by organisational unit, sign-in without invites, Google Groups import, verification.
Workspace policies and branding
The five enforced behaviours, the deferred verdict, the URL scan service, branding and the branded add-in, report inboxes, alert recipients and analysts, and Outlook versus Gmail coverage.
Incidents, alerts and integrations
What becomes an incident, severities, alert cadence, and feeding events to ticketing and SIEM tools.
Platform coverage and user freedom
Outlook and Gmail on desktop, web and mobile, what other clients cannot do, and what a user can still change.
Response actions: mail platforms, gateways, identity, chat and paging
What each integration lets you do, in one table, then per integration: what you need, the vendor-side and console set-up step by step, and the actions with scope and undo. Eight mail platforms and gateways, three identity providers, Slack, Teams, PagerDuty and Opsgenie.
Scam Check Guides
Run a scam-awareness check across your team or your customers: create the campaign, send the personal links from your own address, read the results.
Sending the links: your Microsoft 365 mailbox, Gmail, Outlook, Teams, Slack or one by one
One personal link per person, sent from your own address. Connect a Microsoft 365 mailbox for one-click sending and automatic reminders, or pair links with people, download the mail-merge file and follow the five-minute steps for the tool you already use.