Legal
Security & Trust
Security is the product, so it is also the standard we hold ourselves to. Here is where SecNode runs, what it can reach, how the agents behave, and how we protect our own systems.
Last updated September 2026
Where SecNode runs
SecNode is hosted and managed in the EU on SecNode's own infrastructure, with a dedicated single-tenant option. Your environment model, findings, and evidence stay in the EU. Hosted in the EU today; deploy inside your own boundary on the enterprise tier.
The model
SecNode AI is SecNode's own model, built for security reasoning, and it runs on SecNode's EU-resident infrastructure rather than on a third-party provider's endpoint. It cannot be switched off or changed by another provider's decision.
It is not trained on your code, your environment, or anything the agents find there. The Memory Layer, the persistent model of your environment that the agents read from and write to, is context for reasoning about your company and is never used as training data.
What the agents can reach
SecNode needs read-only access to your code, cloud, and documentation to build the Memory Layer and keep it current. Testing runs only against targets inside a scope you declare, and that scope is enforced at runtime: nothing out of bounds is touched.
How the agents operate
Agents are non-destructive by default. Intrusive actions sit behind approval gates, so a human decides before anything sensitive runs. Every action an agent takes is logged, timestamped, and attributable, so you can review exactly what was done and when.
A finding reaches your queue only once it has been verified with a working reproduction. Social engineering and physical testing are out of scope, and denial-of-service or other volumetric testing is never run.
Data protection
SecNode is GDPR-compliant: lawful processing, data-processing agreements, and data-subject workflows are handled by default, and the platform is DORA and NIS-2 aligned. Personal data handled through this website is described in our Privacy Policy; data you connect to the platform is processed on your instructions under the customer agreement and a data processing agreement, with SecNode acting as processor.
Our own security
We hold our own surface to the standard we hold everyone else's. Our Vulnerability Disclosure Program at secnode.ai/security sets out scope, safe harbour, and response timelines, with an intake form that files reports straight into our security team's queue. Reports can also go to security@secnode.ai, and machine-readable contact details are published at /.well-known/security.txt.
Security reviews and questionnaires
If your procurement or security team has questions this page does not answer, write to sales@secnode.ai. A security engineer answers, not a sales rep.