Security
Sequences runs your robot policies, benchmarks and evaluations on machines we operate, and you connect real robots to them. This page explains how we keep your data and your workloads separate and safe, and how to reach us about security.
How your workloads are isolated
- Each worker runs in its own isolated container and serves a single deployment. Different customers' code never shares a worker.
- Your code runs without access to our platform credentials or control systems.
- A simulation result is not a safety certificate. How to run real robots safely with the service is set out in the Terms (section 7) and the Acceptable Use Policy.
Encryption
- The website, the console and the API are served only over HTTPS.
- Your robots connect to your workers over TLS. Each worker's certificate belongs to your deployment alone, and our SDK checks it by its fingerprint, so a connection cannot be silently redirected to another machine.
- Data is stored with infrastructure providers that encrypt it at rest.
Access to your data
- Database access is controlled row by row: each account can read only its own records, and the key the public website uses cannot read form submissions or any account's data.
- API keys are stored only as hashes; we cannot read your keys back. Revoke a key in the console at any time.
- Access by our staff is limited to the people who need it.
- Every account has an audit log of the actions taken on it.
Your data
- We do not use your content to train models.
- Your data is stored in the United States. By default your workloads run in the region nearest your robots, which may be outside the United States; you can pin a deployment to a region when you deploy it.
- Requests to hosted models and observations sent to your policies are not stored after they are served, unless you turn on recording or capture.
- Content you delete is kept for seven more days so that a deletion made by mistake can be undone if you ask us, then purged. How long we keep each kind of data is set out in our Privacy Policy.
Reporting a vulnerability
Email founders@generalsequences.com with what you found and how to reproduce it. We will reply within 3 business days and keep you informed until it is fixed. If you make a good-faith effort to avoid privacy violations, data destruction and service interruption, test only against your own account, and give us reasonable time to fix the problem before you disclose it, we will not take legal action against you for your research. Do not run denial-of-service tests, social engineering, or tests against other customers' accounts or data. Our security.txt is at /.well-known/security.txt.
Compliance
- Certifications: we do not hold a SOC 2 report or any other security certification. This page describes what we actually do today.
- Service status: generalsequences.com/status/.