Security

Security is the product's credibility.

Runwei™ holds the financial journey of entrepreneurs who have often been underserved by institutions. They trust the platform with that data, and institutions rely on it as evidence. Both depend on the controls below.

Compliance status

Runwei™ operates SOC 2-aligned controls. We are not yet audited or certified, and we say so plainly. An attestation path is part of our current security program.

Controls

What is in place today.

Verified in code, not in slideware. These are the controls the platform runs every day.

Encryption

Passwords are hashed with bcrypt. Sensitive profile fields are encrypted at rest. All traffic runs over HTTPS.

Authentication and sessions

JWT authentication with 24-hour expiry and server-side session revocation, so a session can be ended immediately.

Role-based access

Access is enforced at the API by role: entrepreneur, partner, and administrator each see only what their role allows.

No credentials in the browser

Browser clients and extensions never carry service credentials. Every call goes through authenticated, rate-limited server-side proxies.

Audit trail

Administrative actions and record changes are logged. Nothing unreviewed is ever published to end users.

Abuse protection

Sign-up and contact forms are protected against automated abuse, disposable addresses, and repeated attempts.

Data stewardship

The proof belongs to the community. The data stays theirs.

  • No advertising and no lead marketplace. Entrepreneur data is never sold.
  • Entrepreneurs use the platform free and keep control of their profile, saved, and applied activity.
  • Institutions receive evidence for their obligation, aggregated wherever the obligation allows.
  • Identifiable records shared only where the regulator requires them, and with the consent of the entrepreneur.

To report a vulnerability or request a security review, use the contact form and mark the subject Security.

Primary CTA

Questions for our security team?

Institutional security reviews receive an architecture overview with trust boundaries, a control inventory, and sanitized configuration on request.