Security at Runwaiy
How we protect your financial data
Overview
Runwaiy handles sensitive financial data. We take that responsibility seriously. Here's exactly how your data is protected.
Infrastructure Security
Encryption at rest
All data is encrypted at rest using AES-256 encryption. This is the same standard used by major banks and financial institutions.
Encryption in transit
All data between your browser and our servers is encrypted using TLS 1.3. We enforce HTTPS on every connection — unencrypted connections are rejected.
Data isolation
Every user's data is isolated using Row Level Security. It is technically impossible for one user to access another user's data — this is enforced at the database level, not just in application code.
Hosted in Europe
Your data is stored on servers in the European Union, compliant with UK GDPR data residency requirements.
Access & Authentication
Protecting your account
- Passwords are hashed using bcrypt — we never store or see your plain text password. Even our own team cannot access your password.
- Two-factor authentication (2FA) is available for all accounts using any TOTP authenticator app (Google Authenticator, Authy, 1Password).
- Rate limiting and brute force protection prevents automated login attacks on your account.
Your Data
What we do (and don't do) with your data
✓ What we do
- • Your data is used only to power your Runwaiy dashboard
- • You can export or delete all your data at any time from Settings
- • AI insights use your data only at the moment of generation — nothing is retained by Anthropic
✗ What we don't do
- • We never sell your data to third parties
- • We never share your data with advertisers
- • Your data is never used to train AI models
GDPR
Runwaiy is built for UK businesses and is fully compliant with UK GDPR and the Data Protection Act 2018.
Your rights as a data subject:
- • Right to access your data
- • Right to correct inaccurate data
- • Right to delete your data
- • Right to data portability
- • Right to object to processing
To exercise any of these rights, contact us at privacy@runwaiy.com or use the account deletion feature in Settings → Security.
Responsible disclosure
Found a security issue?
If you've found a vulnerability in Runwaiy, please email us at security@runwaiy.com.
We will respond within 48 hours and work to fix confirmed issues promptly. We ask that you give us reasonable time to address issues before any public disclosure.
This page was last updated March 2026. We review our security practices regularly and update this page when practices change.