Certifications
-
SOC 1 Type I
Status: Certified
Coverage: Design of controls supporting customer financial reporting
Last audit: August 2026
-
SOC 1 Type II
Status: Certified
Coverage: Effectiveness of controls supporting customer financial reporting
Last audit: August 2026
-
SOC 2 Type I
Status: Certified
Coverage: Design of controls for security, availability and confidentiality
Last audit: August 2026
-
SOC 2 Type II
Status: Certified
Coverage: Effectiveness of controls for security, availability and confidentiality
Last audit: August 2026
Security measures
-
Product Security
Secure platform built by design
Product Security
Description:
Security is embedded throughout the Runa platform—from architecture and authentication to deployment and monitoring.
Highlights:
- Secure application architecture
- Environment isolation
- Least-privilege design
- Defense-in-depth principles
-
Data Protection
Encrypting data at every layer
Data Protection
Description:
Customer information is protected using modern encryption standards while stored and transmitted. Sensitive information is isolated using customer-specific encryption controls where appropriate.
Highlights:
- AES-256 encryption at rest
- TLS encryption in transit
- Secure key management
- Customer data isolation
-
Access Management
Access limited to authorized users
Access Management
Description:
Access to production systems is limited to authorized personnel based on business need. Administrative access is protected with multiple layers of authentication and periodic access reviews.
Highlights:
- Role-based access control
- Multi-factor authentication
- Least privilege
- Periodic access reviews
-
Infrastructure
Secure, scalable cloud infrastructure
Infrastructure
Description:
Runa operates on Amazon Web Services using highly available, fault-tolerant cloud infrastructure designed for scalability and resilience.
Highlights:
- AWS-hosted platform
- Multi-AZ architecture
- Infrastructure as Code
- Containerized workloads
-
Network Security
Protected networks and secure connectivity
Network Security
Description:
Production systems are protected through network segmentation, restricted access, secure private networking, and layered security controls.
Highlights:
- Private networking
- Restricted inbound access
- VPN connectivity
- Web application protections
-
SDLC
Security integrated into development
SDLC
Description:
Security is integrated into every stage of software development—from design through deployment—to help ensure code quality and platform reliability.
Highlights:
- Peer code reviews
- Automated testing
- Secure CI/CD
- Version control
-
Incident Response
Continuous monitoring and rapid response
Incident Response
Description:
Our engineering teams continuously monitor platform health and security events. Incidents follow documented response procedures with root cause analysis and continuous improvement.
Highlights:
- Continuous monitoring
- Automated alerting
- Incident response
- Post-incident reviews
-
Business Continuity
Prepared for unexpected disruptions
Business Continuity
Description:
Business continuity and disaster recovery procedures are designed to help maintain service availability and support rapid recovery during unexpected events.
Highlights:
- Backup strategy
- Disaster recovery planning
- Recovery testing
- Service restoration procedures
-
Security Testing
Regular testing and vulnerability management
Security Testing
Description:
Runa continuously evaluates its security posture through automated testing and independent security assessments.
Highlights:
- Vulnerability scanning
- Penetration testing
- Patch management
- Security remediation
-
Privacy
Privacy-first, compliance-driven operations
Privacy
Description:
Runa aligns its security program with recognized industry frameworks and maintains policies designed to protect customer privacy and support regulatory compliance.
Highlights:
- SOC-aligned controls
- Privacy program
- Customer transparency
- Compliance documentation
-
Reliability
Reliable infrastructure with high availability
Reliability
Description:
The platform is engineered for reliability using redundant infrastructure, automated scaling, and continuous operational monitoring.
Highlights:
- High availability
- Auto scaling
- Fault tolerance
- Operational monitoring
-
Risk Management
Continuous assessment and risk reduction
Risk Management
Description:
Security risks are continuously evaluated, prioritized, and addressed through governance processes, audits, and ongoing improvements.
Highlights:
- Risk assessments
- Security reviews
- Continuous improvement
- Governance practices
Documents
- Pentest Attestation letter 2026-27
- Pentest Report
- AWS System and Organization Controls SOC 2 Report
- AWS System and Organization Controls SOC 1 Report
- Bridge Letter
- Security Manual
- SOC 1 Type 1 2026-27
- SOC1 Type II 2026-27
- SOC 2 Type 1 2026-27
- SOC 2 Type II 2026-27
- Subprocessor List
Frequently asked questions
How does Runa protect customer data?
Runa protects customer data through multiple layers of security, including encryption, strict access controls, continuous monitoring, vulnerability management, and regular independent security assessments. Our security program is designed to safeguard the confidentiality, integrity, and availability of customer information.
Is customer data encrypted?
Yes. Customer data is encrypted both in transit and at rest using industry-standard encryption technologies.
Does Runa perform independent penetration tests?
Yes. Runa undergoes regular independent penetration testing performed by qualified third-party security firms. Identified findings are reviewed, prioritized, and remediated through our security management process.
How does Runa identify security vulnerabilities?
Runa maintains an ongoing vulnerability management program that includes automated scanning, regular security reviews, dependency management, and independent security assessments.
Does Runa monitor its platform for security events?
Yes. Our platform is continuously monitored to help detect, investigate, and respond to potential security events.
Does Runa support Multi-Factor Authentication (MFA)?
Yes. Runa supports Multi-Factor Authentication to help customers strengthen account security.
Does Runa support Single Sign-On (SSO)?
Yes. Single Sign-On is available for eligible plans, allowing organizations to integrate authentication with their identity provider.
Where is customer data hosted?
Runa uses enterprise-grade cloud infrastructure designed to provide high availability, scalability, and security for customer data.
Does Runa back up customer data?
Yes. Customer data is backed up as part of our business continuity program to help support data recovery when necessary.
Does Runa have a disaster recovery program?
Yes. Runa maintains documented disaster recovery and business continuity procedures designed to support service resilience.
Which security certifications does Runa maintain?
Runa maintains independent security certifications and regularly undergoes external assessments to validate its security controls. Current certifications and reports are available through our Trust Center or upon request.
Does Runa provide a Data Processing Agreement (DPA)?
Yes. Customers may request a Data Processing Agreement as part of their contractual documentation.
How does Runa support compliance?
Runa helps customers meet payroll, HR, and privacy obligations through security controls, auditability, and features designed to support applicable regulations.
Who owns customer data?
Customers retain ownership of their data. Runa processes customer information only for the purpose of delivering contracted services and in accordance with applicable agreements.
Can customers export their data?
Yes. Customers can export their data according to product capabilities and contractual agreements.
Can customer data be deleted?
Yes. Customer data may be deleted in accordance with contractual obligations and applicable legal requirements.
Does Runa use customer data to train public AI models?
No. Customer data is not used to train public AI models without the customer's authorization.
How does Runa protect information processed by AI features?
AI features are governed by security and privacy controls designed to help protect customer information and support responsible AI practices.
Does Runa use subprocessors?
Yes. Runa works with carefully selected subprocessors to support cloud infrastructure, communications, payments, and other operational services. A complete list is available in our Trust Center.
How are subprocessors evaluated?
All subprocessors undergo security and privacy reviews before being approved and are periodically reassessed as part of our vendor management program.
How can I report a security vulnerability?
If you believe you have identified a potential security vulnerability, please contact our Security Team using the information provided in this Trust Center. We investigate all credible reports and work to address verified issues promptly.
US-EN
Argentina (AR)
Brazil (BR)
Chile (CL)
Colombia (CO)
Ecuador (EC)
Mexico (MX)
Perú (PE)