/
PrivacyImprintTerms
RUNSHIFT
ProductPricingDemoSecurityIntegrations
Open system

SECURITY DOCUMENT

TECHNICAL & ORGANIZATIONAL MEASURES

The controls represented by the current RUNSHIFT product architecture.

TENANT AND ACCESS BOUNDARY

Workspace-scoped row-level security, active-membership checks and role/authority controls limit product data and administrative actions to authorized workspace users.

CREDENTIAL PROTECTION

HubSpot OAuth credentials remain server-side. Stored OAuth credentials are encrypted with AES-GCM. Token material is not returned to the browser or included in customer exports.

DATA MINIMIZATION

RUNSHIFT limits source processing to evidence required by the canonical model and configured capabilities. The HubSpot connector does not require call transcripts or email bodies.

AUDIT AND ADMINISTRATION

Security/admin audit is separated from Operating Memory. Administrative privacy operations have explicit authorization boundaries and lifecycle records.

EXPORT AND DELETION

Authorized workspace export and deletion workflows are implemented. Customer deletion covers workspace-owned source, evidence, mechanic, rule and test data, subject to minimal accountability retention required by documented legal/security policy.

LOGGING MINIMIZATION

The product design avoids intentionally placing CRM payloads, uploaded row contents, observation text, model context, OAuth tokens, authorization headers or client secrets into application logs.

BACKUP AND RECOVERY

A documented restore runbook defines required recovery evidence and acceptance criteria. Provider-specific backup configuration, region and completed restore evidence are verified against the deployed production environment and are not invented on this page.

RUNSHIFT

See what repeats. Change what drives it.

ProductPricingDemoSecurityIntegrationsSystem
PrivacyImprintTerms
A product of FOCX GmbH© 2026 RUNSHIFT