Security

Protection should be understandable, not mysterious.

ScreenPact uses Windows permissions, a protected background service and local-only management to preserve the family agreement. Technical details below were reviewed for v1.2.3 on August 17, 2026.

Passcodes are not recoverable text

ScreenPact stores a salted password verifier in a protected system location. The original six-digit passcode cannot be read back from it.

  • PBKDF2-SHA256 verifier
  • Restricted Windows permissions
  • No passcode in general settings reads

Sensitive actions are service-authorized

Opening a page is not enough to change protection. The protected service independently requires recent parent authorization.

  • Disabling protection
  • Increasing time
  • Changing schedules
  • Changing the passcode

Configuration writes are recoverable

Settings are written atomically and a backup copy is retained. If both copies are unusable, ScreenPact pauses protection and keeps the internet available so a parent can reconfigure safely.

  • Atomic writes
  • Backup recovery
  • Clear parent warning

Local management boundary

The dashboard listens on this Windows PC only. ScreenPact v1.2.3 does not provide phone, LAN or cloud administration.

  • Loopback-only web UI
  • No remote family dashboard
  • No browsing uploads
!

Early release signing status

The current installer is not digitally signed. Windows can display Unknown publisher. Signing and public download reputation remain pre-release work; do not interpret the current package as independently audited software.

Responsible reporting

If you believe you found a security issue, email support@screenpact.com. Describe the version, Windows edition, account type, expected result and observed result. Do not send credentials, family activity or exploit code to public channels.