Security & Privacy
Practical safeguards. Clear boundaries.
Accounts and access
Public signup sends account details to the Runexus server. Passwords are hashed with bcrypt before storage. RuneForge uses authenticated access for customer workspaces, and administrator pages require separate authorization.
Provider credentials are handled on the server rather than embedded in public browser code. The marketing service sets browser protections including a Content Security Policy and restrictions on framing.
Bounded public scanning
The scanner validates public network destinations and applies redirect, timeout and response-size limits. It does not sign in to scanned sites or solve CAPTCHAs. A blocked source remains an access limitation, not a negative business finding.
Business facts stay under owner control
Site Agent drafts remain private until the owner approves and publishes a release. Public machine answers use that published release. A public scan does not grant access to a customer’s Rune or unpublished facts.
Data practices and security questions
The Privacy notice explains signup data, scan processing, Runa messages and browser storage. To report a suspected security issue or ask about these practices, email runa@runexus.io. Include a description without passwords, access tokens or private customer data.
This page describes current implementation practices. It is not a certification or independent security audit.