Custodos is live: every leading AI model, your data stored securely in Switzerland.Start free trial
Privacy & security

Security mode

Security mode is a switch in the chat for particularly sensitive conversations, for example with client or HR data. Admins offer it and choose the model. The chat then follows stricter rules that members cannot change.

Last checked on 28 September 2026

On this page

What applies in security mode

A chat in security mode shows a status line naming the model and stating that details are pseudonymised and no web search takes place. For that chat:

AreaIn security mode
ModelOnly the model the admin chose. The model picker is locked and shows Fixed by security mode.
Personal dataPseudonymisation is always on, even if scanning is switched off for the workspace. Every category is replaced, including those the workspace otherwise ignores. Blocked categories stay blocked. Send original is disabled.
Company BrainPassages from brains are pseudonymised before they reach the model, whatever the brain's own setting.
Web searchnone
Connected accountsThe model does not access cloud files, email or calendars.
Imagesno image attachments and no image generation
Context cachethe Standard duration at most

Setting up security mode

  1. 1

    Open the settings

    As an admin, click Settings and go to the Security mode section.
  2. 2

    Choose the model

    Under Model used in security mode, pick one of the chat models your workspace allows that lie within its region. Every choice in this section is saved immediately.
  3. 3

    Offer the mode

    Turn on Offer security mode. The switch then appears in the chat. Without a chosen model, the mode cannot be offered.
  4. 4

    Set the default

    Optional: with New chats start in security mode, every new chat begins in security mode. This suits law firms and fiduciary or tax advisory offices, where that is the norm.

Switching it on and off in the chat

Members switch the mode on for a single chat with Turn security mode on. This works at any time, including in a chat already under way. From then on, the model no longer receives images from earlier messages.

The mode can only be switched off while the chat has no messages yet. After that, Custodos shows Cannot be switched off in a chat that has started – open a new chat. This way, pseudonymised and non-pseudonymised messages never sit in the same chat.

When settings change

  • The admin stops offering the mode: new chats can no longer switch it on. Chats already running in security mode keep all its rules.
  • The chosen model is unavailable: the chat does not answer and never falls back to another model. Custodos shows The model for security mode is not available. Ask an admin to set one under Settings.
  • The model is blocked: if an admin blocks the security mode model on the Models page, Custodos also removes it and switches the mode off.
  • The region is narrowed: if the model lies outside the new region, Custodos removes it and switches the mode off. An admin has to choose a new model and offer the mode again.
  • Credits have run out: the economy model answers here too, a low-cost model from the allowed models in the workspace's region. Pseudonymisation, region and the locked picker stay in place.

When security mode does not apply

  • It only covers chats where the switch is on. All other chats follow the workspace's normal settings.
  • Pseudonymisation has the same detection limits as elsewhere. Whatever the rules do not detect leaves unchanged in security mode too. See Protecting personal data.
  • When credits have run out, the reply comes from the economy model among the allowed models in the workspace's region rather than from the chosen one.
  • The mode does not move processing elsewhere. Where the model processes is decided by the chosen model and the processing region.

Read next

Still have a question? Write to us.