audit rights dpa residency · Privacy Policy
RightNow policy finding
“ We implement industry-standard security controls: TLS 1.2+ in transit, AES-256 at rest, role-based access control with hardware-key 2FA for production access, row-level security for tenant isolation, continuous logging and monitoring, dependency and secret scanning on every CI build, and annual third-party penetration testing. The full controls program is documented on the Security page . Independent attestation. RunInfra is SOC 2 Type II attested. The audit report is available to current customers and qualified prospects under NDA at trust.rightnowai.co or by request to jaber@runinfra.ai . Breach notification. In the event of a personal data breach affecting your Personal Information, we will notify you without undue delay, and in any case within 72 hours of becoming aware of the breach. The notification will describe the nature of the breach, the categories and approximate number of records concerned, the likely consequences, and the measures we are taking to contain and remediate. This commitment applies regardless of where you reside and matches the GDPR Article 33 standard. Use a strong, unique password or sign in with Google or GitHub, and keep your API keys secret. We urge you to keep your credentials safe and to log out after each session on shared devices. No method of transmission over the Internet or method of electronic storage is 100% secure, and the controls above mitigate but do not eliminate risk.”
- Document
- Privacy Policy
- Captured
- 2026-09-25
- Location
- Article III (HOW WE PROTECT INFORMATION)
- Snapshot SHA-256
- b6309c245f206c1edde76a0077b157521e325b7334ed0c95cdd96c21ce48bf20
Informational only, not legal advice. Terms change; verify the source and capture date.