Security

A privacy company promising to protect your privacy is the lowest possible bar. This page outlines what we actually do to clear it.

  • GDPR Compliant
  • SOC 2 In progress
  • ISO 27001 In progress

Your data stays yours.

Export it, delete it, and stay in control at every step. Nothing you search is used to train AI models, and we never sell your data. Not to advertisers, not to brokers, not to anyone.

Read the privacy policy

Export anytime

Download everything Serus holds about you, straight from your account, whenever you want.

Delete at will

Close your account and wipe your data whenever you choose. No hoops, no waiting.

No AI training

Your data is never used to train AI models. It stays yours, and only works for you.

Data protection & controls

With industry best practices, and operational controls, we're more than fully committed to the safety and confidentiality of your data.

Infrastructure security

  • Unique authentication enforced
  • Encryption key access restricted
  • Production application access restricted

Infrastructure security

  • Unique authentication enforced
  • Encryption key access restricted
  • Production application access restricted
  • Secrets managed in a dedicated store
  • Storage closed to the public internet
  • Hosted in the EU

Product security

  • Application-level encryption utilized
  • Role-based access enforced
  • Data encrypted in transit

Product security

  • Application-level encryption utilized
  • Role-based access enforced
  • Data encrypted in transit
  • Data encrypted at rest
  • Automated checks run on every pull request

Organizational security

  • Confidentiality agreements signed
  • Security awareness training completed
  • Access revoked upon offboarding

Internal security procedures

  • Continuity and disaster recovery plans established
  • Risk assessments conducted
  • Database backups configured

Internal security procedures

  • Continuity and disaster recovery plans established
  • Risk assessments conducted
  • Database backups configured
  • Object versioning enabled
  • Infrastructure logs retained
  • Systems monitored for errors and downtime

Data and privacy

  • Data retention procedures established
  • Customer data deleted upon leaving
  • Data export available on request

Data and privacy

  • Data retention procedures established
  • Customer data deleted upon leaving
  • Data export available on request
  • Data subject requests fulfilled
  • Consent recorded and versioned
  • Personal data segregated by customer

Transparency

  • Privacy policy established
  • Data processing agreements in place
  • Subprocessors documented and published

Privacy used to be the default. You were unknown to most people most of the time, and that was simply how life worked. It stopped being true so gradually that nobody got the chance to object.

Serus is an attempt to put it back. Not as a setting you toggle, and not as a promise you have to take on faith, but as work that happens whether you're thinking about it or not.

Our mission

Frequently asked

Is your data encrypted?

Yes. All datastores are encrypted at rest, with app-level encryption on sensitive data, and every transmission uses TLS 1.3 or higher. Access to encryption keys is restricted to the systems that need them.

Is Serus SOC 2 compliant?

SOC 2 certification is in progress. We partner with third-party firms for regular audits and report status as it changes rather than claiming a certification we do not yet hold.

Is Serus GDPR compliant?

Yes. Serus runs on GDPR-compliant infrastructure, and we protect your data, organize evidence for compliance, and honor the rights of people living in the EU.

Is Serus ISO 27001 compliant?

ISO 27001 certification is in progress alongside SOC 2. Both are long-term security investments rather than short-term growth plays, and we will publish each one when it is complete.

Who inside Serus can access my data?

Access is role-based and least-privilege: unique authentication per person, restricted encryption keys, and an authorization hierarchy that grants no more than a role requires. Access is logged.

What happens to my data when I leave?

Data retention, deletion, and classification policies govern the full lifecycle. Customer data is deleted upon leaving, and secure asset disposal with maintained inventories covers the hardware side.

Do you sell my data or train AI on it?

No. We never sell your data, and nothing you search is used to train AI models.

Cookie preferences

Choose which categories we may use. Full details for every cookie are in our Cookie Policy.

Strictly necessary

Authentication, session management, security and fraud prevention, and saving your consent choice. Always active. The site cannot function without them.

Functional

Remember preferences such as language and settings that improve your experience.

Analytics

Help us understand how the site is used, like pages visited, interactions, and performance, so we can improve it.

Marketing & advertising

Measure our marketing and deliver more relevant ads through partners such as Google, Meta, TikTok, X, and Reddit. Used only with your consent.

Your choice is saved for 12 months and applies across serus.ai, including the app. You can change it anytime from the cookie widget or the "Cookie settings" link in the footer. Withdrawing consent does not affect processing that happened before withdrawal.