Privacy Policy
How RuntimeAI collects, uses, and protects your information.
Last updated: September 2026
Information We Collect
RuntimeAI collects information necessary to provide our AI governance platform services. This includes:
- Account Information โ Name, email address, company name, and role when you create an account or request a demo.
- Usage Data โ Telemetry about platform usage, feature engagement, and performance metrics, collected in aggregate and anonymized.
- Agent Metadata โ Agent identity tokens, policy enforcement logs, and governance audit trails processed through the platform.
- Communications โ Information you provide when contacting support or submitting partner applications.
We do not collect, store, or process the content of AI agent prompts or responses unless explicitly configured by the tenant administrator for audit purposes.
How We Use Your Information
We use collected information solely for:
- Providing and improving the RuntimeAI platform and services
- Processing account registration and demo requests
- Sending service-related communications (security alerts, maintenance notices)
- Generating anonymized, aggregate analytics to improve product quality
- Complying with legal obligations and regulatory requirements
We never sell your personal information to third parties. Marketing communications are opt-in only.
Data Security
RuntimeAI implements enterprise-grade security measures aligned with SOC 2 Trust Service Criteria control mappings โ a self-attested control-mapping practice, not a third-party certification claim:
- Encryption โ AES-256 at rest, TLS 1.3 in transit, FIPS 140-2 validated modules
- Access Control โ Role-based access with multi-factor authentication
- Audit Logging โ Immutable, tamper-evident audit trails for all data access
- Tenant Isolation โ Strict multi-tenant data isolation at the database, network, and application layers
- Incident Response โ 24/7 security operations with documented incident response procedures
On request and under NDA, RuntimeAI provides a compliance documentation package โ including a CISA Secure Software Development Framework (SSDF) self-attestation, SOC 2 Trust Service Criteria control mappings, a current threat model, and a software bill of materials (SBOM) โ so your own auditors can verify these practices directly rather than rely on a third-party certificate.
Data Sovereignty & Residency
RuntimeAI supports configurable data sovereignty controls:
- Regional Deployment โ Choose your data residency region (US, EU, APAC, or custom)
- Air-Gapped Option โ Our Fortress and Sovereign tiers support fully air-gapped, on-premises deployment โ the model we recommend for customers who need maximum data sovereignty and want zero dependency on RuntimeAI-hosted infrastructure
- Cross-Border Controls โ Configurable data transfer policies with transparency reporting
- Right to Deletion โ Tenant administrators can request complete data deletion at any time
Your Rights
Under applicable privacy laws (GDPR, CCPA, and others), you have the right to:
- Access your personal data and obtain a copy
- Correct inaccurate personal data
- Request deletion of your personal data
- Restrict or object to processing
- Data portability in machine-readable format
- Withdraw consent at any time
To exercise these rights, contact us at privacy@runtimeai.io.