Security
Last updated 6 October 2026
How Browser Rules protects your organisation's data: checks inside the browser, Azure hosting, strong sign-in, and data kept apart for every organisation.
Browser Rules is a security product, so protecting your information, and that of the people using your browsers, comes first. These are the answers to the questions we’re asked most.
Checked in the browser
- Downloads, ZIP files and clipboard text are checked inside the browser. Files are never uploaded.
- A browser that isn’t enrolled in the admin console sends nothing anywhere.
- Organisations choose in their Privacy settings how much detail their browsers report: full addresses, addresses without the query, or only the website, with or without the page, clipboard text, pause reasons and who it was.
- All the extension’s code is in the package reviewed by the Chrome Web Store. It downloads its policies as data, never code.
- The extension’s policies and settings are kept where web pages can’t read or change them.
- Each browser receives only the policies that apply to its user, never your organisation’s list of users or groups.
Microsoft Azure
The admin console and its database are hosted on Microsoft Azure in the UK South region (London), in data centres with physical security and independent certifications.
- All data is encrypted in transit (TLS, with HTTPS enforced).
- The database and its backups are encrypted at rest (transparent data encryption).
- The database has point-in-time backups, so it can be restored to an earlier moment if needed.
Signing in to the admin console
- Two-factor authentication for everyone: every admin sets up an authenticator app before using the console. Passkeys are supported too.
- Strong passwords: at least 12 characters, and passwords known from data breaches are refused (checked anonymously against Have I Been Pwned; the password itself never leaves the console).
- Lockout: five wrong passwords lock an account for 15 minutes.
- Confirmation for sensitive changes: changing how you sign in, or deleting your account, asks you to confirm it’s you unless you signed in moments ago.
- Sessions: sign-in cookies are sent only over HTTPS, can’t be read by scripts, and every change carries a token that stops other websites making it on your behalf.
Your organisation’s data
- Kept apart: every organisation’s data is separated in the database itself. Every read and every change is checked against the organisation it belongs to.
- Roles: owners, admins and read-only members, so people get only the access they need.
- Changes recorded: policy changes, unlocks, revoked browsers, new enrolment keys and members are recorded in your organisation’s audit log, with who made them.
- Browsers: each enrolled browser has its own token, which we store only in a form that can’t be used to sign in. Enrolment attempts are rate limited so keys can’t be guessed. Any browser can be revoked, and the enrolment key replaced, without affecting the others.
Support access
Our support team can see your organisation’s console only when one of your owners allows it, for 1, 7 or 30 days, read only. Each visit is recorded in your audit log, and owners can end access at any time.
Our team
- Two-factor authentication on all our accounts, including Microsoft Azure.
- Access to systems and data only for the people who need it to run and support the service.
- We don’t sell your data: our business is paid subscriptions.
- Security and privacy are considered first when we build new features.
FAQs
How long do you keep data?
Audit events: for your organisation’s retention period: 30 days on the Free plan, a year on the Paid plan. They are then deleted automatically.
Enrolled browsers and their users: until your organisation removes them, or its account closes.
Admin console accounts: until they are deleted.
Backups: 35 days, then gone.
How can I report a security issue?
Email [email protected]. Please include enough detail for us to reproduce it. We’ll reply promptly and keep you informed while we fix it.
Have you had an incident that resulted in a data breach?
No. If one ever happens, we will notify the customers affected and publish a full report.
Does Browser Rules replace antivirus?
No. It’s an extra layer in the browser, where many attacks begin. Keep your antivirus, email filtering and updates. What it can’t protect is listed in What it can and can’t protect.