Last updated: July 24, 2026
We describe here how we approach security today. We only state what we actually do — where we haven't completed a formal certification or capability yet, we say so rather than imply otherwise. For specifics about your use case, contact us.
Data handling
- Your content is yours. Prompts and outputs you send through the gateway are processed to serve your request. We do not use your content to train models, and we do not sell it.
- Content vs. operational metadata. Separate from prompt/response content, we keep operational metadata — request counts, token usage, latency, and error codes — to run billing, reliability, and support. What we retain and for how long is described in the Privacy Policy.
- Encryption in transit. Traffic to our website and API is served over HTTPS/TLS.
- Access control. Access to systems and data is limited to authorized personnel on a need-to-know basis; API keys are yours to rotate and revoke.
Payments & PCI
When paid checkout is available, card payments will be handled by established third-party payment processors using hosted checkout. Runix does not store full card numbers on its servers, which keeps card data out of our environment and reduces PCI scope.
Application & secrets
- Secrets and provider credentials are kept in server-side configuration, never exposed to the browser or embedded in client code;
- We follow least-privilege principles for internal access to keys and infrastructure.
Compliance status
We want to be precise here rather than impressive: Runix has not yet completed formal third-party certifications such as SOC 2 or ISO 27001, and we do not claim them. If your procurement process requires specific attestations, DPAs, or a security questionnaire, talk to us and we'll tell you honestly what we can support today and what's on the roadmap.
Responsible disclosure
If you believe you've found a security vulnerability, please email [email protected] with the details and steps to reproduce. Please give us reasonable time to investigate and remediate before any public disclosure. We appreciate good-faith research and will not pursue action against researchers who act responsibly.
Contact
Security questions: [email protected]