Your browser is the target.
We protect it.

Modern attacks don't need malware. They trick you into handing over access yourself. Intersafe stops them before they start.

What we protect against

The most dangerous attacks today don't exploit software vulnerabilities. They exploit people. Attackers build convincing fake pages that trick users into running commands, pasting credentials, or granting access. These are called social engineering attacks, and they are the fastest-growing threat category on the web.

ClearFake / ClickFix / and more

Fake browser update, verification, or sponsored search pages that secretly copy a malicious PowerShell or terminal command to your clipboard, then instruct you to paste and run it.

Credential theft

Pages that trick you into opening DevTools and pasting session tokens, API keys, cookies, or authorization codes. Targets GitHub, Slack, Google, AWS, and more.

Fake CAPTCHAs

Convincing "I'm not a robot" or "Verify you are human" overlays that are actually social engineering traps designed to make you execute hidden commands.

Phishing and malware sites

Known dangerous URLs checked against a local database of over 1 million threats, plus Google Safe Browsing for real-time coverage of new threats.

How the detection works

Clipboard protection. When a page tries to write to your clipboard using JavaScript, Intersafe intercepts the content and scans it against a database of known malicious command patterns. If a match is found, the write is blocked and you see a warning. This stops ClearFake and ClickFix attacks at the moment they try to plant the payload.

Download-and-run protection. Some attacks skip the clipboard entirely: a page quietly saves a file to your Downloads folder, then instructs you to open and run it. Intersafe recognizes this pattern and warns you to delete the file before it can execute.

Credential detection. Intersafe recognizes patterns for JWT tokens, GitHub tokens, Slack tokens, Google OAuth tokens, AWS access keys, Bearer tokens, session cookies, and other sensitive credentials. If a site tries to copy these to your clipboard, the operation is blocked immediately. Attackers can't steal what they can't extract.

Page scanning. Every page is scanned for social engineering signals: fake verification prompts, paste instructions, Win+R or terminal commands, Cloudflare impersonation, and DevTools manipulation requests. Popup overlays with high z-index values get extra scrutiny. When multiple signals appear together, Intersafe flags the page.

Behavioral analysis. Some attacks don't match known patterns. Intersafe watches for suspicious combinations of behavior: hidden input fields paired with fullscreen overlays, rapid clipboard access patterns, and pages that try to look like system dialogs. This catches new attack variants before they make it into pattern databases.

URL protection. Every site you visit is checked against a local copy of up to 1 million known threat URLs. This check happens entirely on your device. In rare cases where a partial match is found, an anonymous hash prefix (never the full URL) is sent to Google Safe Browsing for confirmation.

Security checkup. Intersafe reviews your browser settings, installed extensions, and privacy configuration. It flags risky permissions, outdated security settings, and extensions with excessive access, and checks every installed extension against a list of known-malicious extensions. Pro users can apply safer defaults with one click.

Known-malicious extension data is sourced from chrome-mal-ids by The Privacy Commons Institute (CC BY 4.0).

We built Intersafe because we saw people getting tricked by attacks that antivirus software ignores. These aren't viruses. They're well-designed web pages that exploit trust. Your browser is where you're most vulnerable, and it's where protection should live.

What Intersafe is

Intersafe is a browser extension - software that runs locally on your device. It sits in the same product category as ad blockers, password managers, and VPN clients. Detection and blocking happen automatically, in the browser, with no human involvement. There are no support agents, no remote assistance, and no phone lines. You install the extension and it protects you in the background.

Built for privacy

Your data is yours. We never sell it, never share it, and we designed every feature to work without it ever leaving your browser.

No data collection* Your browsing history, clipboard, and page content never leave your device
No tracking* Zero analytics or third-party scripts on the extension or website
No paywalled security Every protection feature works on the free plan. Paid plans add convenience, not safety

*When a threat is blocked, Intersafe sends a single anonymous count to verify protection is working. No user, device, or URL data is included. Registered users' allowed domains list is synced in encrypted form that we cannot read to allow sync between devices.

Pattern updates

New attacks appear all the time. Intersafe automatically updates the latest detection rules so you're always protected. No data about you or your browsing is ever sent back.

Open permissions

Intersafe requires browser permissions to function. Here's exactly what each one does:

Every permission is used for protection. Nothing else.