/
PrivacyImprintTerms
RUNSHIFT
ProductPricingDemoSecurityIntegrations
Open system

SECURITY DOCUMENT

SECURITY OVERVIEW

A concise enterprise view of the current RUNSHIFT security and data boundary.

DATA FLOW

Source CRM or structured import → read-only/source adapter → canonical deal/evidence model → recurring mechanics → operating rules → controlled changes → tests and history.

SOURCE ACCESS

HubSpot V1 is read-only. Optional source capabilities increase evidence coverage but do not change the engine or authorize CRM write-back.

AUTHORIZATION AND TENANT BOUNDARY

Workspace-scoped access controls, active membership and role/authority checks separate customer data and privileged actions.

CREDENTIAL HANDLING

OAuth credentials remain server-side and are encrypted at rest within the connector's credential store. Tokens are not returned to browser state.

DATA MINIMIZATION

RUNSHIFT does not require email bodies, call transcripts, unrestricted CRM field access, employee scores or psychological profiles to operate the current product.

AI BOUNDARY

Server-side model calls are limited to candidate-generation/planning functions and receive explicitly constructed structural context. OAuth token material is excluded from that context.

PRIVACY OPERATIONS

Authorized workspace export and deletion workflows are implemented. See the Privacy Notice and DPA / AVV.

AUDIT AND RECOVERY

Security/admin audit is separate from Operating Memory. Backup and restore follow a documented runbook; production evidence is verified for the deployed environment before customer onboarding.

DOCUMENTATION

Technical & Organizational Measures · Subprocessor List

RUNSHIFT

See what repeats. Change what drives it.

ProductPricingDemoSecurityIntegrationsSystem
PrivacyImprintTerms
A product of FOCX GmbH© 2026 RUNSHIFT