Security
A privacy company promising to protect your privacy is the lowest possible bar. This page outlines what we actually do to clear it.
- GDPR Compliant
- SOC 2 In progress
- ISO 27001 In progress
Your data stays yours.
Export it, delete it, and stay in control at every step. Nothing you search is used to train AI models, and we never sell your data. Not to advertisers, not to brokers, not to anyone.
Read the privacy policyExport anytime
Download everything Serus holds about you, straight from your account, whenever you want.
Delete at will
Close your account and wipe your data whenever you choose. No hoops, no waiting.
No AI training
Your data is never used to train AI models. It stays yours, and only works for you.
Data protection & controls
With industry best practices, and operational controls, we're more than fully committed to the safety and confidentiality of your data.
Infrastructure security
- Unique authentication enforced
- Encryption key access restricted
- Production application access restricted
Product security
- Application-level encryption utilized
- Role-based access enforced
- Data encrypted in transit
Organizational security
- Confidentiality agreements signed
- Security awareness training completed
- Access revoked upon offboarding
Internal security procedures
- Continuity and disaster recovery plans established
- Risk assessments conducted
- Database backups configured
Data and privacy
- Data retention procedures established
- Customer data deleted upon leaving
- Data export available on request
Transparency
- Privacy policy established
- Data processing agreements in place
- Subprocessors documented and published
Privacy used to be the default. You were unknown to most people most of the time, and that was simply how life worked. It stopped being true so gradually that nobody got the chance to object.
Serus is an attempt to put it back. Not as a setting you toggle, and not as a promise you have to take on faith, but as work that happens whether you're thinking about it or not.
Our missionFrequently asked
Is your data encrypted?
Yes. All datastores are encrypted at rest, with app-level encryption on sensitive data, and every transmission uses TLS 1.3 or higher. Access to encryption keys is restricted to the systems that need them.
Is Serus SOC 2 compliant?
SOC 2 certification is in progress. We partner with third-party firms for regular audits and report status as it changes rather than claiming a certification we do not yet hold.
Is Serus GDPR compliant?
Yes. Serus runs on GDPR-compliant infrastructure, and we protect your data, organize evidence for compliance, and honor the rights of people living in the EU.
Is Serus ISO 27001 compliant?
ISO 27001 certification is in progress alongside SOC 2. Both are long-term security investments rather than short-term growth plays, and we will publish each one when it is complete.
Who inside Serus can access my data?
Access is role-based and least-privilege: unique authentication per person, restricted encryption keys, and an authorization hierarchy that grants no more than a role requires. Access is logged.
What happens to my data when I leave?
Data retention, deletion, and classification policies govern the full lifecycle. Customer data is deleted upon leaving, and secure asset disposal with maintained inventories covers the hardware side.
Do you sell my data or train AI on it?
No. We never sell your data, and nothing you search is used to train AI models.