Security
Your client list and your prices are the business. We treat them that way.
This page describes what Rundown does to protect your data, in plain terms, and is upfront about what we do not have yet.
Each shop's data is separate
Every record belongs to one organization, and every query is scoped to it on the server. An automated test suite checks that one tenant can never read another's data.
Permissions enforced on the server
Owner, admin, office, sales, tech, subcontractor and read-only roles. Checks run in the backend, not just in the interface, so hiding a button is never the only protection.
Cost and margin are redacted
Unit costs, margins and vendor pricing are removed from responses for roles that should not see them. Techs and subcontractors never receive those fields.
Vendor logins are sealed
Distributor credentials are encrypted with a data key for your organization. They are never returned to the browser, including to you.
Card data never touches Rundown
Payments use Stripe's hosted fields. Card numbers go from your client's browser to Stripe. We do not see or store them, and receipts never show a full card number.
Sign-in with MFA
Authentication is handled by Clerk. Multi-factor authentication is available to every user, with a list of active sessions and forced sign-out.
An audit log you can export
Changes to financial records and permissions, data exports and any support access to your account are logged. The log cannot be edited.
Public links are hard to guess
Proposal, payment and portal links use 256-bit random tokens. They can be revoked and can expire. Public forms are rate limited and protected against bots.
Verified webhooks
Incoming events from Stripe, Clerk, Twilio and Resend are checked by signature and processed once.
Backups and export
The database is backed up nightly and backups are kept for 30 days. You can export every record type to CSV yourself, on any plan.
Messaging compliance built in
Opt-in state is recorded per contact with source and time. STOP and HELP are handled automatically. Automated texts hold during quiet hours.
No AI training on your data
AI features send only the fields needed for the task to our model provider, never card data. Neither we nor the provider train models on it.
What we do not have yet
No badges we have not earned.
- We do not have a SOC 2 report. Rundown is a pilot build from a small team, and we would rather say so than imply otherwise.
- Single sign-on is part of the Enterprise plan and is set up per customer.
- Key bitting and credential records are not in the product yet. When they are, they will be encrypted at the field level, limited by role, and every view will be logged.
Subprocessors
Who else handles your data.
These providers process data under contract so that Rundown can run. We give notice before adding one.
The full terms are in the data processing addendum.
- Clerk
- Sign-in, organizations, sessions and MFANames, emails, credentials, session data
- Convex
- Application database, file storage and server functionsAll tenant data stored in Rundown
- Stripe
- Subscription billing and Connect paymentsBilling contacts, payment and payout records. Card numbers go to Stripe directly and never reach Rundown
- Twilio
- SMS delivery and phone numbersPhone numbers, message bodies, delivery status
- Resend
- Transactional and automation emailEmail addresses, message bodies, delivery status
- Anthropic
- AI parsing and drafting (Claude models)Only the fields needed for the task. Not used to train models
- Google Maps Platform
- Address lookup, geocoding and mapsSite addresses
- Sentry
- Error monitoringError traces and technical metadata
- PostHog
- Product analyticsUsage events and device metadata
Report a problem
Found a vulnerability?
Write to security@rndwn.app with the steps to reproduce it. Please give us a reasonable chance to fix it before you share it publicly, and do not access data that is not yours. We will reply to every report.