Security

Security for operational process data

Runova stores guides, process steps and screenshots from the systems your team uses. Access is separated by workspace and controlled by role.

Workspaces are isolated

Workspace membership and permissions control signed-in access to shared company records and files.

Google Cloud infrastructure

Cloud records and files are stored in me-central1 (Doha, Qatar). Backend services run in Doha and Iowa, United States. Google Cloud encrypts stored data at rest, and HTTPS protects data in transit. Local browser drafts and extension recordings are not separately encrypted by Runova.

Google sign-in

Authentication runs through Google. Runova does not receive or store Google passwords.

What the extension captures

It does
  • Activate only during a recording or playback you start
  • Capture the clicks in that recording, with each page's address, title and nearby labels
  • Send the result to your workspace alone
It does not
  • Observe browsing outside an active recording
  • Store passwords or values typed into form fields
  • Sell your recordings or collect your browsing history

Screenshots are images of your screen. Where a page displays real customer data, avoid recording it or mask the values first.

Access inside your company

A workspace has an owner, admins and members. What each person can create, edit, assign or delete follows from their role and permissions, checked on the server as well as in the interface.

Access inside Runova

Workspace permissions restrict access inside the product. Authorized Runova backend services and cloud administrators can still access readable data; this is not customer-only end-to-end encryption. Human access is limited by our support, acceptable-use and legal policies. Our service providers are described in the Privacy Policy.

Deletion and export

Deleting a guide removes it and its screenshots; deleting a workspace removes its content. Account deletion requests are completed within 30 days. Processes are held as structured data, so if you ask us for an export of your processes and guides we will send you one.

Certification

Runova does not hold a SOC 2 report or ISO 27001 certificate, and does not claim to. If your organisation requires formal certification before engaging a supplier, ask and you will get a direct answer on where that stands.

Reporting a vulnerability

Email pilot@runova.ae with enough detail to reproduce the issue.