Our first teams are live on Runi. We’re onboarding the next group now.Onboarding new teams now.Get access →

Trust

Security at Runi

How Runi protects what your team’s agents learn.

Updated 26 September 2026

Runi holds what your team’s coding agents learn, which can say a lot about how you build software. Runi is built and run by its two founders, Aymen and Ravi, and that shapes how it’s protected: two people hold access to production, every change ships through one of us, and when you write to us about security, the person who reads it wrote the code.

We haven’t been through a SOC 2 or ISO 27001 audit yet, so instead of a badge, this page tells you exactly what is in place.

Your machine decides what leaves it

Runi never scans, indexes or uploads your repository, and never reads your git history. The daemon on your computer applies your ignore rules and redacts recognised secrets before anything is shared, and an ignored file is never even named. Each person chooses, in Settings on their own computer, how much of their prompts, their agent’s work and its reasoning reaches the team. Redaction is defence in depth, not a promise that every possible secret format is caught.

No model sees your content on our side

We send no workspace content to any AI model provider. Where Runi uses a model, for example to write a brief, it runs through the agent command-line tool you already use, on your own computer, under your own agreement with that provider.

Where your data lives

  • Workspace, account and billing state are stored with Supabase in the United States (US East, Northern Virginia), on infrastructure audited to SOC 2. Transfers from the UK and the EEA rest on the safeguards set out in our privacy policy.
  • Card details are entered with Stripe and never reach Runi.
  • Every subprocessor, and what it sees, is listed in our privacy policy.

Isolation between teams

Every table is protected by Postgres row-level security scoped to workspace membership, and access ends the moment membership does. Tables only our servers use are kept outside the API entirely. An adversarial test suite checks isolation with every change. Roles (owner, admin, member, observer) are enforced on the server, not in the app.

Encryption

Data is encrypted in transit with TLS, and our websites require HTTPS. Data at rest is encrypted by our infrastructure providers. The desktop app is code-signed, and it verifies every update’s signature before installing it.

Secrets and access

  • Production secrets live only in our providers’ secret stores, never in code or in the app.
  • Two people have access to production: the founders. Nobody else does.
  • Customer workspace content is accessed only to answer a support request you made or to handle an incident.

How we build

Every change is version-controlled and must pass type checks, the full test suite and the database isolation tests before it ships. Database changes are reviewed migrations, replayed from scratch in the test suite.

Retention and deletion

Activity is deleted after 90 days, and finished sessions after 30. Cards and records stay until you delete them or the workspace. Deleting a workspace removes its content, and deleting your account removes your account data. Details are in the privacy policy.

Incidents

Security incidents are handled by the founders themselves. If one affects your data, you hear about it from one of us directly, as data protection law requires.

Reporting a vulnerability

Email [email protected] with “Security” in the subject. It goes straight to the founders. Please do not access other people’s data or degrade the service; testing against your own account is welcome. Our contact details are also in security.txt.

Security documentation

Customers and prospective customers can ask for our security answers and vendor list at [email protected].

Questions about this page?

They go straight to Aymen and Ravi, the two people who run Runi. You’ll get a real answer, usually within hours.