Security mode
Security mode is a switch in the chat for particularly sensitive conversations, for example with client or HR data. Admins offer it and choose the model. The chat then follows stricter rules that members cannot change.
Last checked on 28 September 2026
On this page
What applies in security mode
A chat in security mode shows a status line naming the model and stating that details are pseudonymised and no web search takes place. For that chat:
| Area | In security mode |
|---|---|
| Model | Only the model the admin chose. The model picker is locked and shows Fixed by security mode. |
| Personal data | Pseudonymisation is always on, even if scanning is switched off for the workspace. Every category is replaced, including those the workspace otherwise ignores. Blocked categories stay blocked. Send original is disabled. |
| Company Brain | Passages from brains are pseudonymised before they reach the model, whatever the brain's own setting. |
| Web search | none |
| Connected accounts | The model does not access cloud files, email or calendars. |
| Images | no image attachments and no image generation |
| Context cache | the Standard duration at most |
Setting up security mode
- 1
Open the settings
As an admin, click Settings and go to the Security mode section. - 2
Choose the model
Under Model used in security mode, pick one of the chat models your workspace allows that lie within its region. Every choice in this section is saved immediately. - 3
Offer the mode
Turn on Offer security mode. The switch then appears in the chat. Without a chosen model, the mode cannot be offered. - 4
Set the default
Optional: with New chats start in security mode, every new chat begins in security mode. This suits law firms and fiduciary or tax advisory offices, where that is the norm.
Switching it on and off in the chat
Members switch the mode on for a single chat with Turn security mode on. This works at any time, including in a chat already under way. From then on, the model no longer receives images from earlier messages.
The mode can only be switched off while the chat has no messages yet. After that, Custodos shows Cannot be switched off in a chat that has started – open a new chat. This way, pseudonymised and non-pseudonymised messages never sit in the same chat.
When settings change
- The admin stops offering the mode: new chats can no longer switch it on. Chats already running in security mode keep all its rules.
- The chosen model is unavailable: the chat does not answer and never falls back to another model. Custodos shows The model for security mode is not available. Ask an admin to set one under Settings.
- The model is blocked: if an admin blocks the security mode model on the Models page, Custodos also removes it and switches the mode off.
- The region is narrowed: if the model lies outside the new region, Custodos removes it and switches the mode off. An admin has to choose a new model and offer the mode again.
- Credits have run out: the economy model answers here too, a low-cost model from the allowed models in the workspace's region. Pseudonymisation, region and the locked picker stay in place.
When security mode does not apply
- It only covers chats where the switch is on. All other chats follow the workspace's normal settings.
- Pseudonymisation has the same detection limits as elsewhere. Whatever the rules do not detect leaves unchanged in security mode too. See Protecting personal data.
- When credits have run out, the reply comes from the economy model among the allowed models in the workspace's region rather than from the chosen one.
- The mode does not move processing elsewhere. Where the model processes is decided by the chosen model and the processing region.
Read next
Still have a question? Write to us.
