Updated 12 August 2026
Security at RUNR8
Read-only connections
Provider credentials are used only to read billing and usage metadata. RUNR8 does not proxy model traffic or write to provider systems.
Credential protection
Connector credentials use envelope encryption: each connector has a unique data key, and those keys are wrapped by an application master key stored outside the database.
Tenant isolation
Every product query and mutation is scoped to the active organization. Administrative actions require an organization administrator role.
Data minimization
The product is designed around billing metadata. Individual tool-spend detail is restricted to administrators and excluded from ordinary reports by default.
Report a concern
Send security reports to security@runr8.ai. Do not include customer data or live credentials in the initial message.