Legal
Privacy Policy
Read how Secto secures and handles your data.
This Privacy Policy explains how Secto AI, Inc. ("Secto", "we", "us", or "our") processes information through our browser extensions, mobile and desktop applications, administrative console, website, and related support services. We refer to them together as the "Services".
1. Scope and customer-managed deployments
Secto is an enterprise browser security service. An organization such as your employer may deploy and configure Secto, decide which security policies apply, and review security events in its administrative console. For information processed on behalf of a customer organization, that organization controls the deployment and generally determines the purposes of processing. Its privacy notices and internal policies may also apply.
When we process information for our own website, sales, support, account administration, security, and service-improvement purposes, Secto is responsible for that processing.
2. Information we process
Account, organization, and enrollment information
We may process names, work email addresses, company names, contact details, customer and tenant identifiers, browser or device identifiers, deployment identifiers, extension or application versions, enrollment status, and managed configuration values. This information connects an installation to the correct customer account and policies.
Browser security and policy events
When Secto is enrolled and a configured policy applies, the extension may report security and enforcement events to the customer's Secto tenant. Depending on the feature and policy, an event may include:
- the page URL, hostname, referrer URL, source and destination of a redirect, timestamp, and detected application or service;
- the detection type, policy mode, action taken, and whether the user continued, ignored, blocked, redirected, or replaced content;
- event context such as navigation, redirect, tab, form submission, file upload or download, clipboard, and password-entry event types;
- browser extension inventory information such as extension ID, name, version, state, permissions, and icon; and
- browser, operating system, extension version, and diagnostic identifiers needed to operate and troubleshoot the Services.
Secto uses this information to enforce customer policies, investigate threats, show administrators what occurred, maintain the extension, and prevent duplicate or fraudulent events.
Content inspected by browser protections
Secto may inspect webpage content, page structure, URLs, cookies, password-entry events, clipboard content, AI prompts, and file-upload context to apply the policies configured by the customer organization.
- AI data protection: Prompt and upload inspection runs in the browser. Enforcement telemetry can include the detection reason, AI provider, URL, submission type, policy mode, and action. Secto does not send the full prompt as part of this enforcement telemetry.
- Password protection: Password values are fingerprinted locally for comparison and are not sent to Secto. A resulting event may include the associated work email address, service, URL, policy mode, and action.
- Phishing and cookie analysis: Page content and cookie patterns may be inspected locally to identify phishing and adversary-in-the-middle techniques. Cookie values are not included in the security event sent to Secto.
- Malicious copy and paste protection: If this control triggers, the detected clipboard text, matched indicators, URL, policy mode, and action may be reported to the customer's Secto tenant.
Local event context
The extension keeps a short-lived local event timeline so a detection can be understood in context. It can contain URLs and event types such as navigation, clicks, redirects, form submissions, file activity, and password-entry occurrence. This local timeline automatically expires after approximately 12 hours. When a detection occurs, the relevant portion may be included with the security event sent to the customer's tenant.
Website, sales, and support information
If you visit our website or contact us, we may process your name, work email, phone number, company, message, page URL, and information you choose to provide. Our website uses PostHog to measure page views and selected interactions such as blog engagement and demo requests. We disable automatic interaction capture and session recording. Standard server logs may also contain IP address, browser type, referring page, and request timestamps.
Technical diagnostics
We use Sentry for error monitoring and performance diagnostics. Diagnostic reports may include a pseudonymous installation or browser identifier, extension version, error details, and the active page origin and path. Secto removes email addresses from diagnostic HTML attachments before sending them when that attachment type is used.
3. How we use information
We process information to:
- provide, configure, secure, and support the Services;
- apply customer security policies and report resulting events to authorized administrators;
- detect phishing, credential exposure, risky browser extensions, malicious clipboard activity, unsafe AI usage, and related browser threats;
- maintain service reliability, diagnose errors, prevent abuse, and improve product performance;
- respond to sales, support, privacy, and security requests; and
- comply with law and enforce our agreements.
Where applicable, we rely on our contracts, legitimate interests in providing and securing the Services, consent where required, and compliance with legal obligations.
4. Browser and application permissions
Secto requests browser and operating-system permissions needed for configured security features. These can include access to websites and tabs, scripting, navigation and web requests, cookies, history, downloads, clipboard actions, extension storage, scheduled configuration sync, and native messaging with the Secto host application. We use these permissions to inspect browser activity, enforce policy, display notices, synchronize managed configuration, and report security events as described above.
Available permissions differ by browser and operating system. A customer's policy configuration determines which protections are active.
5. How we disclose information
We may disclose information to:
- the customer organization that deployed Secto and its authorized administrators;
- service providers that support hosting, storage, error monitoring, website analytics, communications, and customer support, including Sentry and PostHog;
- professional advisers and authorities when required to comply with law, protect rights and safety, or investigate abuse; and
- a successor in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate safeguards.
We do not sell personal information. We do not use browser activity or Customer Data for targeted advertising, and we do not share personal information for cross-context behavioral advertising.
6. Retention
We retain customer account and security-event data according to the applicable customer agreement, customer configuration, and legal requirements. We retain website inquiries and support records while needed to respond and for legitimate business records. Diagnostic and analytics providers retain information under their applicable service settings and agreements.
We delete or de-identify information when it is no longer needed, unless we must retain it for security, fraud prevention, dispute resolution, backup integrity, or legal compliance.
7. Your choices and rights
You can disable or uninstall the extension or application, subject to controls applied by your organization. If your organization manages Secto, contact your administrator about its policies and requests concerning Customer Data.
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information. You may also have the right to withdraw consent or appeal a denied request. Contact us at privacy@secto.io. We may need to verify your identity and direct a request to the customer organization when it controls the relevant data.
8. Security
We use administrative, technical, and organizational safeguards designed to protect information. No system is completely secure, so we cannot guarantee that unauthorized access or loss will never occur.
9. International transfers
Secto and its service providers may process information in the United States and other countries. Where required, we use contractual and other safeguards for international transfers.
10. Children
The Services are intended for organizations and are not directed to children under 13. We do not knowingly collect personal information from children under 13 through the Services.
11. Changes to this policy
We may update this Privacy Policy as the Services or legal requirements change. We will post the updated version here, revise the date above, and provide additional notice when required.
12. Contact us
For privacy questions or requests, contact:
- Secto AI, Inc.
- Email: privacy@secto.io