Skip to content
Sureno
Security

What is protecting you, and who wrote it

Most of Sureno's security is not ours. That is the point — the parts that keep a hostile page away from your machine are Chromium's, unmodified.

The engine is Chromium

Pages are rendered by Blink and V8 inside Electron's bundled Chromium — the same stack Chrome ships. We did not fork it, patch its sandbox, or lower a security default to make a feature easier to build.

Every tab is a separate process

Site isolation and the renderer sandbox are on, as they come. A compromised page is contained the way Chromium contains it, because it is the same containment.

Updates arrive on their own

Chromium security fixes matter only if they reach you. Sureno checks for updates in the background and applies them on quit, so the browser stays current without a dialog you would have dismissed.

The browser UI is isolated from pages

Tabs, omnibox and the assistant run in a session that is separate from the one your pages use. A page cannot reach into the browser chrome around it.

Private windows are genuinely ephemeral

Incognito and guest windows use throwaway Chromium partitions. When the window closes, the partition and everything in it is gone.

Permissions stay per-site

Camera, microphone, location and notifications are asked for per site and revocable per site, using Chromium's permission model rather than one we invented.

What we would want to know before installing a new browser

Three things that are true today and count against us. A security page without them is a marketing page.

The macOS build is not yet notarised by Apple.

On first launch macOS will warn you that the developer cannot be verified, and you have to right-click → Open. That warning is doing its job. Signing and notarisation are in progress; until then, only ever install Sureno from a link on sureno.ai.

The shield counters and the VPN screen are simulated.

They are demonstrations of an interface, they say so inside the app, and they do not protect your network traffic. Treating a simulated shield as real protection is worse than having no shield, which is why they are labelled rather than quietly counted.

We are small and new.

Chrome has been the most attacked piece of consumer software on earth for fifteen years and has held up. We inherit its engine, not its track record. That is a real difference and you should weigh it.

Reporting something

If you find a vulnerability, email support@sureno.ai with enough detail to reproduce it. We will confirm receipt, tell you what we found, and credit you when it is fixed unless you would rather we did not. Please do not test against other people's machines.

Verifying what you downloaded

Every published installer will list its SHA-256 checksum here so you can confirm the file you downloaded is the file we built. Until a build is published on the download page, there is nothing here to check — and you should be suspicious of any Sureno installer you find somewhere else.

Try it for a week alongside Chrome

The import copies your bookmarks and passwords rather than moving them, so Chrome stays exactly as you left it. If Sureno is not for you, uninstalling takes under a minute.

Free · macOS 12 Monterey or later · Apple silicon