SECURITY DOCUMENT
TECHNICAL & ORGANIZATIONAL MEASURES
The controls represented by the current RUNSHIFT product architecture.
TENANT AND ACCESS BOUNDARY
Workspace-scoped row-level security, active-membership checks and role/authority controls limit product data and administrative actions to authorized workspace users.
CREDENTIAL PROTECTION
HubSpot OAuth credentials remain server-side. Stored OAuth credentials are encrypted with AES-GCM. Token material is not returned to the browser or included in customer exports.
DATA MINIMIZATION
RUNSHIFT limits source processing to evidence required by the canonical model and configured capabilities. The HubSpot connector does not require call transcripts or email bodies.
AUDIT AND ADMINISTRATION
Security/admin audit is separated from Operating Memory. Administrative privacy operations have explicit authorization boundaries and lifecycle records.
EXPORT AND DELETION
Authorized workspace export and deletion workflows are implemented. Customer deletion covers workspace-owned source, evidence, mechanic, rule and test data, subject to minimal accountability retention required by documented legal/security policy.
LOGGING MINIMIZATION
The product design avoids intentionally placing CRM payloads, uploaded row contents, observation text, model context, OAuth tokens, authorization headers or client secrets into application logs.
BACKUP AND RECOVERY
A documented restore runbook defines required recovery evidence and acceptance criteria. Provider-specific backup configuration, region and completed restore evidence are verified against the deployed production environment and are not invented on this page.