24 h when scheduled
Virus database
Fresh scanner definitions for known threats.
SafeLayer combines curated updates, network intelligence, cloud fingerprint checks, and its own local reputation into the evidence behind each protection decision.

One local decision core
New intelligence is checked before it becomes evidence on the device.
Four update tracks
Database definitions, signature intelligence, network lists, and the application each update on a cadence appropriate to their role.
24 h when scheduled
Fresh scanner definitions for known threats.
Every hour
Curated malware, phishing, URL, and dangerous-domain intelligence.
Every 6 hours
Local network lists for malicious destinations and command-and-control infrastructure.
Every 24 hours
A separate update track for the SafeLayer application itself.
Validated before use
Every feed is subject to interval controls, identifiable requests, download limits, and validation.
A refresh replaces the active file only when it is ready, preserving the previous version when something goes wrong.
Intelligence that stays accountable
Threat Intelligence