← Back to Seafloor

Security

Last updated: February 2026

1. Isolated Environments

Each Seafloor user gets a dedicated cloud VM. Your agent, conversations, files, and data are isolated from other users. We do not run multi-tenant workloads on shared containers.

2. Encryption

All traffic between your devices and Seafloor is encrypted via HTTPS/TLS. Data at rest on your dedicated server is stored on encrypted volumes provided by our infrastructure provider.

3. Authentication

We use secure, token-based authentication. Passwords are never stored in plaintext. Session tokens are short-lived and transmitted only over encrypted connections.

4. API Proxy

AI model requests flow through our proxy for usage tracking and billing. We log request metadata (timestamps, token counts, model used) but do not store the content of your prompts or completions long-term.

5. Third-Party Services

Seafloor relies on the following third-party providers:

  • Stripe — payment processing (PCI-compliant)
  • DigitalOcean — cloud infrastructure
  • Anthropic — AI model provider
  • Resend — transactional email

Each provider maintains its own security practices and compliance certifications. We encourage you to review their policies independently.

6. What We Don't Do

  • We do not sell your data
  • We do not routinely access your agent's files or conversations
  • We do not share your data with third parties beyond what's listed above

7. Limitations & Disclaimer

Seafloor is a hosted service that gives you a dedicated cloud computer running open-source software. While we take reasonable measures to secure the platform, no system is 100% secure.

You are responsible for anything your agent does on your behalf, including messages it sends, code it writes, and actions it takes through connected channels (WhatsApp, Telegram, Discord, etc.). Seafloor is not liable for unintended agent behavior, data loss, or downstream consequences of agent actions.

We provide the service "as is" without warranty of any kind. Use Seafloor at your own risk and exercise caution when granting your agent access to external services or sensitive data.

8. Reporting Issues

Found a vulnerability or have a security concern? Reach out on X/Twitter @seafloorbot.