Skip to content
SETUROSEarly access
How it worksWhat travelsWorks withPrivacyPricing
Log inStart free
Menu
How it worksWhat travelsWorks withPrivacyPricingLog inStart free

On this page

  1. Who can read what
  2. What is encrypted
  3. What carrying keeps out
  4. Signing in
  5. This website
  6. Compliance
  7. Reporting a vulnerability

Security

Last updated 24 September 2026

Seturos holds the context of your work, so the product is built around one rule: every read is scoped to the person asking, and nothing is read until they ask. This page says how, and where it stops.

Who can read what

  • Every read is scoped to the asking person’s own organisation and their level of access within it. Which organisation you belong to comes from your signed-in session, never from anything a request says about itself.
  • What you carry is yours. Follow a project and its members can read it; everyone else, including the rest of your organisation, cannot.
  • A coding session is filed under the repository it ran in, and a read inside one repository never returns another repository’s sessions, even when both belong to the same project.
  • Actions that send or write on your behalf above your organisation’s risk threshold wait for a person to approve them.

What is encrypted

  • All traffic to app.seturos.com and to this site uses HTTPS.
  • OAuth tokens for the tools you connect are encrypted with AES-256-GCM before they are stored, and decrypted only to do something you asked for. Disconnecting a tool deletes its token.
  • Documents you upload live in private object storage and are reachable only through short-lived signed links issued to your session.
  • Our database and object-storage providers encrypt data at rest.

What carrying keeps out

  • Recognised secrets (API keys, tokens, connection strings) are removed from everything you carry before it is stored.
  • Before a prompt leaves your browser, the extension replaces recognised personal data with placeholders; the map back stays in your browser for fifteen minutes.
  • The extension reads a page only when you carry it or while you follow a project. The desktop app reads what you highlighted when you pressed the shortcut, and never the screen.
  • Both detections are pattern-based. They reduce what is stored and sent; they are not a guarantee, and we do not describe them as one.

Signing in

  • Sign-in is handled by our identity provider. Seturos never stores your password.
  • The browser extension connects to your account with its own token, which we store only as a hash.
  • Model keys you add belong to your organisation and are used only for your organisation’s requests.

This website

seturos.com loads nothing from other origins: fonts are self-hosted, there are no analytics or third-party scripts, and a strict content security policy, frame protection and a no-sniff header are sent with every page.

Compliance

SOC 2 Type II is in progress and not complete. We will not claim a certification before we hold it.

Data processing and business associate agreements will be offered on the Enterprise plan once the company’s registration is complete. A list of the providers that process your data is available on request.

Reporting a vulnerability

Email security@seturos.com with what you found, how to reproduce it, and what you think it affects. We will acknowledge your report and keep you told as we fix it.

While you look, please don’t read or change anyone else’s data, don’t degrade the service for others, and give us a reasonable chance to fix a problem before you describe it publicly.

SETUROS

One memory for the AI tools you work in. Early access, open to everyone from 30 September 2026.

Product

  • How it works
  • What travels
  • Works with
  • Pricing
  • Questions

Trust

  • Privacy policy
  • Security
  • Accessibility
  • Terms of service
  • Cancellation and refunds

Contact

  • support@seturos.com
  • security@seturos.com
  • app.seturos.com
© 2026 Seturos, Inc.No cookies and no tracking on this site.
Seturos