Security
Runwei™ holds the financial journey of entrepreneurs who have often been underserved by institutions. They trust the platform with that data, and institutions rely on it as evidence. Both depend on the controls below.
Compliance status
Runwei™ operates SOC 2-aligned controls. We are not yet audited or certified, and we say so plainly. An attestation path is part of our current security program.
Controls
Verified in code, not in slideware. These are the controls the platform runs every day.
Passwords are hashed with bcrypt. Sensitive profile fields are encrypted at rest. All traffic runs over HTTPS.
JWT authentication with 24-hour expiry and server-side session revocation, so a session can be ended immediately.
Access is enforced at the API by role: entrepreneur, partner, and administrator each see only what their role allows.
Browser clients and extensions never carry service credentials. Every call goes through authenticated, rate-limited server-side proxies.
Administrative actions and record changes are logged. Nothing unreviewed is ever published to end users.
Sign-up and contact forms are protected against automated abuse, disposable addresses, and repeated attempts.
Data stewardship
To report a vulnerability or request a security review, use the contact form and mark the subject Security.
Primary CTA
Institutional security reviews receive an architecture overview with trust boundaries, a control inventory, and sanitized configuration on request.