Identity
MFA-ready authentication, session controls, role management, service identities, and later SAML/SCIM for enterprise plans.
Security and trust
Runlium is in product design and early development. This page documents the intended security architecture and assurance roadmap without claiming certifications or controls that have not been independently completed.
No SOC 2, ISO 27001, HIPAA, GDPR, or other certification is claimed by this starter website.
Launch control targets
These are implementation requirements, not completed-certification claims. Each control needs an owner, evidence, tests, and operational procedures.
MFA-ready authentication, session controls, role management, service identities, and later SAML/SCIM for enterprise plans.
Organization-scoped authorization at every service boundary with database-level policies where practical.
TLS in transit, managed encryption at rest, encrypted backups, and controlled key access in production environments.
Security events, business change history, agent tool calls, approvals, exports, and administrative actions.
Protected branches, code review, dependency scanning, secret scanning, CI checks, staged deployment, and rollback paths.
Backups, restore tests, queues, retries, idempotency, health monitoring, incident procedures, and recovery objectives.
AI-specific controls
Prompt wording alone is not a security boundary. Access must be enforced before retrieval, at tool invocation, during workflow execution, and at the final external action.
Tenant, user, tool, record, and action permissions are explicit.
Sensitive actions pause for authorized human review.
Important answers expose permitted source records and freshness.
Behavior, leakage, tool use, and regressions are tested continuously.
Budgets, limits, model routing, and cost visibility prevent runaway usage.
Models, prompts, tools, approvals, outputs, and side effects are recorded.
Assurance roadmap
The dates will depend on the final architecture, target markets, customer requirements, and operational maturity.
Threat model, data inventory, access reviews, backup restore test, incident plan, vendor register, secure SDLC, logging, and customer-facing subprocessors.
Repeatable access reviews, change evidence, security training, vulnerability management, recovery exercises, incident metrics, and policy operation.
Choose the relevant audit or certification only after product-market requirements are clear and the controls have operated long enough to produce evidence.
Security requirements
For responsible disclosure or security questions, contact security@runlium.cloud.