Book a meeting
Compliance

Built for regulated workloads.

Encrypted at rest and in transit, per-project access control, hard-delete that cascades. SOC 2 Type 2 in progress.

Posture

Where each framework stands.

01

SOC 2 Type 2 — in progress

Runlog is engineered against the SOC 2 Type 2 trust services criteria covering security, availability, processing integrity, confidentiality, and privacy. Technical controls are implemented across access management, encryption, change management, incident response, and vendor risk. We have not yet completed a Type 2 audit and hold no attestation report today; we can share our control descriptions and our current gap list on request.

02

HIPAA — technical controls, no BAA yet

Encryption in transit and at rest, per-project role-based access control, and tenant isolation enforced in the data layer are implemented today. Per-object read-access audit logging is on our roadmap and is not yet in place, so we do not currently sign Business Associate Agreements or accept PHI. We will tell you when that changes rather than let you assume it.

03

ISO 27001 — controls implemented, ISMS not established

Our technical controls are designed against the ISO/IEC 27001 control set. The management system around them — the documented policy suite, the formal risk-assessment cadence, the internal audit programme — is not yet established, and we are not certified or in a certification process. We will not describe ourselves as ISO-aligned until the ISMS exists.

04

On-prem and customer-managed deployment — specified, not shipped

For customers whose data and inference must never leave their own perimeter, we have a designed and documented on-prem architecture: the relay running inside the customer's VPC, content encrypted at rest under a customer-held key, and all model traffic routed through the customer's own LLM provider account. It is a specification, not a product you can deploy today — no customer is running it. The managed offering runs on Google-managed encryption at rest with standard zero-data-retention provider terms. If on-prem is a hard requirement for you, talk to us about a design-partner engagement; we will not sell you a deployment that does not exist.

05

Data residency and deletion

Customer data lives in per-project isolated namespaces, enforced in the data-access layer rather than at the API edge. Deletion is a hard delete — no archive collections — and cascades through every derived asset: source files, content chunks, extracted evidence regions, entities, and facts. Formal GDPR and CCPA machinery (a data-subject export endpoint and erasure tombstones) is on our roadmap and not yet shipped.

Talk to us

Need a security questionnaire answered or a sub-processor list? We reply within one business day, and where the honest answer is “not yet,” that is the answer you get.

security@runlogai.com