Last Updated: May 2026
Privacy Policy
RunSec is built for security teams who treat source code as sensitive. This policy explains what we collect, what stays on your machine, and how we protect information that reaches RunSec Hub.
Data minimization
We do not store your raw source code on our servers. Your repositories remain under your control; RunSec is designed so that full file contents are not persisted in the Hub as part of normal operation.
How analysis works
Code analysis happens locally via the RunSec MCP server in your IDE or CI environment. Only metadata and finding summaries — such as severity, rule identifiers, file paths, line references, and proof-of-concept snippets you choose to include — are synced to RunSec Hub for reporting and collaboration.
Encryption and integrity
All data in transit between your environment and RunSec Hub is protected with TLS encryption. Finding payloads submitted to the Hub are HMAC-sealed so we can detect tampering and verify authenticity of uploaded reports.
Analytics and telemetry
We use minimal telemetry to improve scan accuracy and product reliability — for example, aggregate error rates, rule performance signals, and anonymized usage patterns. We do not sell personal data, and we do not use telemetry to reconstruct your source code.
Contact
Questions about this policy? Email [email protected].