Security and trust

Trust claims should follow evidence—not marketing pressure.

Runlium is in product design and early development. This page documents the intended security architecture and assurance roadmap without claiming certifications or controls that have not been independently completed.

Architecture baselineIn design and implementation
Founding launch controlsRequired before production customer data
Independent assurancePlanned after stable operations and evidence collection

No SOC 2, ISO 27001, HIPAA, GDPR, or other certification is claimed by this starter website.

Launch control targets

Security foundations for the first production customers.

These are implementation requirements, not completed-certification claims. Each control needs an owner, evidence, tests, and operational procedures.

01

Identity

MFA-ready authentication, session controls, role management, service identities, and later SAML/SCIM for enterprise plans.

02

Tenant isolation

Organization-scoped authorization at every service boundary with database-level policies where practical.

03

Encryption

TLS in transit, managed encryption at rest, encrypted backups, and controlled key access in production environments.

04

Auditability

Security events, business change history, agent tool calls, approvals, exports, and administrative actions.

05

Secure delivery

Protected branches, code review, dependency scanning, secret scanning, CI checks, staged deployment, and rollback paths.

06

Resilience

Backups, restore tests, queues, retries, idempotency, health monitoring, incident procedures, and recovery objectives.

AI-specific controls

Models are one component inside a controlled execution system.

Prompt wording alone is not a security boundary. Access must be enforced before retrieval, at tool invocation, during workflow execution, and at the final external action.

Scope

Tenant, user, tool, record, and action permissions are explicit.

Approval

Sensitive actions pause for authorized human review.

Evidence

Important answers expose permitted source records and freshness.

Evaluation

Behavior, leakage, tool use, and regressions are tested continuously.

Economics

Budgets, limits, model routing, and cost visibility prevent runaway usage.

Audit

Models, prompts, tools, approvals, outputs, and side effects are recorded.

Assurance roadmap

Publish only what can be supported with evidence.

The dates will depend on the final architecture, target markets, customer requirements, and operational maturity.

Phase 1

Founding launch

Threat model, data inventory, access reviews, backup restore test, incident plan, vendor register, secure SDLC, logging, and customer-facing subprocessors.

Phase 2

Operational evidence

Repeatable access reviews, change evidence, security training, vulnerability management, recovery exercises, incident metrics, and policy operation.

Phase 3

Independent assurance

Choose the relevant audit or certification only after product-market requirements are clear and the controls have operated long enough to produce evidence.

Security requirements

Founding customers can shape deployment, retention, identity, audit, and data-residency priorities.

For responsible disclosure or security questions, contact security@runlium.cloud.

Share your requirements