Criticalscore 97 · flagged Thursday, October 1, 2026

fidelityandsecurity.app

Appeared in the .app zone on Thursday, October 1, 2026; by the end of that day the census found active website. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

brand in the name
matched: fidelity
+30
lure words (login, verify, secure…)
matched: security
+26
brand name at a retail registrar
matched: 1&1 Internet SE
+8
brand name and brand-styled page
matched: fidelity
+15
form on a brand-styled page
matched: has_form
+18
Registrar
1&1 Internet SE
Nameserver provider
Nameservers
ns1025.ui-dns.com, ns1088.ui-dns.de, ns1111.ui-dns.biz, ns1121.ui-dns.org
First-day state
active website
HTTP status
200
Page title
Fidelity and Security - Gestionale
Has a form
yes
Brand echoed
fidelity

Model opinions

Second opinionlooks benignconfidence 86%· claude-opus-5-5

This is the internal management portal of an Italian private-security firm called "Fidelity and Security". It has its own eagle-shield logo, a codice fiscale login, and staff modules such as guard shift scheduling, patrol interventions, EasyPlan/Sabanet history and absence requests. Nothing references Fidelity Investments' branding, accounts or financial services, so the 'fidelity' match is a coincidental business name, not impersonation.

First passlooks like phishingtarget: Fidelityconfidence 95%· claude-haiku-4-5

The domain impersonates Fidelity with a login page titled 'Accedi a Fidelity' (Log in to Fidelity) using Fidelity branding and a shield logo, requesting credentials (codice fiscale/username and password) that post to the same domain with no legitimate Fidelity infrastructure present. The sealed-room architecture—password form posting to self with no offsite links—is the classic phishing shape.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Thursday, October 1, 2026

Screenshot of fidelityandsecurity.app taken by the zone census on 2026-10-01

Same data as JSON: /api/zone/domain/fidelityandsecurity.app. This page is not indexed by search engines and does not link to the site it describes.