All Features
Govern · Security & Compliance

Security and compliance

Append-only audit logs, role-based access control, data encryption, and workspace isolation. Built with SOC 2 requirements in mind, with certification on our roadmap.

What Security & Compliance gives you

Every Important Action, Permanently Recorded

Activity tracking for compliance requirements, matching the scope described below: every important action, not every read.

Exactly Who Can Reach What

Role-based access, permission overrides, and app-level restrictions.

Encrypted Without Anyone Configuring It

Data encrypted at rest and in transit. Industry-standard protection.

Cloudflare In Front, Workspaces Apart

Cloudflare's network in front of every app, and workspaces isolated from each other.

Why Security & Compliance matters

How Security & Compliance works

Compliance in Runwork is part of the architecture. Append-only audit logs, role-based access control, data encryption and workspace isolation are all built in, so the evidence a review asks for already exists rather than being assembled afterwards.

Comprehensive audit logging tracks every important action in your workspace. Who changed what data, when permissions changed, what modifications were made. This audit trail is essential for SOC 2 Type II compliance, which requires demonstrable evidence of security controls over time. The logs are append-only and queryable: entries are written once and are not edited afterwards, and you can search the full history.

Access controls provide the principle of least privilege. Team management includes role-based access (Owner, Admin, Editor, Viewer), user groups for bulk permissions, and fine-grained overrides for specific users or apps. You control exactly who can access what, and every access change is logged.

Data encryption protects information at rest and in transit. All data stored in Runwork is encrypted using industry-standard algorithms. All network traffic uses TLS encryption. The enterprise infrastructure includes DDoS protection and network isolation.

Frequently Asked Questions

Is Runwork SOC 2 Type II compliant?
SOC 2 Type II compliance is on our roadmap. Runwork is built with SOC 2 requirements in mind from the ground up: comprehensive audit logging, role-based access controls, data encryption, and documented security procedures. We plan to pursue formal certification as the company grows.
What security controls does Runwork provide?
Role-based access control with fine-grained permissions, append-only audit logs tracking every action, and data encryption at rest and in transit. Customer traffic routes through Cloudflare's network, so volumetric attacks are absorbed there before they reach your apps. These controls are built in and on by default.
How does Runwork handle data encryption?
All data stored in Runwork is encrypted at rest using industry-standard algorithms. All network traffic uses TLS encryption in transit. Encryption is automatic and always-on, with no configuration required. This ensures your data is protected regardless of where it's stored or transmitted.
Can I use Runwork in regulated industries?
Runwork is designed for enterprise use in security-conscious environments. The comprehensive audit logging, access controls, and encryption give you the audit trail, access controls and encryption evidence that security questionnaires ask for. Whether that satisfies a specific regime is a question for your compliance team, and we will answer whatever they need to ask. For certifications beyond SOC 2, contact us.

Use Cases

Enterprise sales Regulated industries Security-conscious customers Vendor assessments

Related Features

See How Teams Use Security & Compliance

Ready to try Security & Compliance?

One shared cloud under the AI tools your team already uses.