Security

Financial data deserves careful protection.

RunwayCal uses technical and operational safeguards designed to protect the financial information businesses use for planning and decisions. This page focuses on controls available in the current service and states the important boundaries directly.

Protection built into the current service.

Security depends on several boundaries working together: how a person signs in, which workspace they can reach, how requests are checked, and how sensitive connection details are handled.

01

Encrypted transport

The production website and application are delivered over HTTPS so information is protected while it travels between a supported browser and RunwayCal.

02

Managed authentication

Account sign-in, email confirmation, password recovery, supported OAuth sign-in, and session refresh use managed authentication services.

03

Workspace access checks

Server-side identity, role, permission, and organization checks protect workspace operations. Missing or unrecognized roles fail closed rather than gaining access.

04

Scoped request boundaries

Production requests use explicit origin controls and request-rate safeguards. Workspace queries are scoped to the organization making the request.

05

Sensitive-field redaction

Known sensitive fields are removed or masked from application logs to reduce the chance that credentials or private values appear in diagnostic output.

06

Provider credential handling

Where a supported connection stores an API key or OAuth token, current credential-writing paths use application-layer encryption. The exact authorization boundary remains provider-specific.

Access follows the workspace and the permission.

Interface controls are backed by server-side checks. Customers remain responsible for choosing who joins a workspace, assigning appropriate access, protecting credentials, and reporting suspected account misuse.

01

Account access

People sign in through their own account. Workspace membership and assigned access determine which organization data and actions are available.

02

Administrative changes

Sensitive workspace and membership actions require the relevant owner or administrative permission rather than relying on a visible interface alone.

03

Read-only sharing

Where a read-only board-viewing path is used, the access boundary is separate from an editable workspace session.

The protection boundary follows the feature being used.

RunwayCal connects financial planning inputs without claiming that every provider works the same way. Provider documentation and the in-product connection flow define what a connection can read, receive, import, or send.

01

Financial and planning data

RunwayCal handles the workspace inputs and outputs needed for the features a customer chooses to use. Recorded, expected, planned, and hypothetical values retain different meanings inside the product.

02

Connected services

Each integration has its own authorization and data boundary. A connection does not create a universal bank feed, automatic reconciliation, or write access to every external system.

03

Subscription payments

The payment provider handles payment-card transactions. RunwayCal receives the subscription, entitlement, and transaction-status information needed to administer access without needing a full card number.

Connections and accounts can be removed through controlled workflows.

Disconnecting a supported integration removes the locally stored connection credential. Some providers may also require revocation at the provider. An authorized workspace owner can initiate account deletion; an active paid subscription is canceled first, and the workflow fails closed if that cancellation cannot be confirmed.

A completed deletion removes active organization data through the product workflow. Protected backups, security records, or information required by law may remain for a limited period as explained in the Privacy Policy. RunwayCal does not promise instantaneous removal from every backup or third-party system.

Clear boundaries are part of trustworthy security communication.

RunwayCal does not currently claim SOC 2, ISO 27001, a published penetration-testing cadence, a zero-trust certification, a universal data-residency commitment, or an uptime SLA. No online service can guarantee absolute security or uninterrupted availability.

Security and privacy practices evolve with the service. Current personal-information handling, retention, and user-rights boundaries are described in the Privacy Policy.

Turn your financial reality into better business decisions.

Use RunwayCal with the access and provider boundaries described here.