Information Security Addendum
This Runlayer Information Security Addendum (the "ISA") sets forth the technical and organizational measures that Runlayer has implemented and maintains to safeguard Customer Data Processed by Runlayer in the provision of the Services. Capitalized terms used but not defined in this ISA have the meanings assigned to them in the Master Services Agreement (the "MSA") between Runlayer and Customer or in the Runlayer Data Processing Agreement (the "DPA").
1. SCOPE
This ISA applies to Runlayer's Processing of Customer Data in connection with the provision of Services to Customer.
2. INFORMATION SECURITY PROGRAM
2.1 Program. Runlayer maintains a written information security program (the "Information Security Program") that includes administrative, technical, physical, and organizational measures designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access. The Information Security Program is aligned with industry-standard frameworks (i.e., SOC 2 Type II, NIST Cybersecurity Framework).
2.2 Management Direction. Runlayer has a designated qualified member of its workforce with requisite knowledge and experience in information security to be responsible for the development, implementation, and maintenance of the Information Security Program.
2.3 Organization of Information Security. Runlayer assigns responsibilities related to the Information Security Program with appropriate segregation of duties to reduce opportunities for unauthorized or unintentional access to, modification of, or misuse of Runlayer's assets and Customer Data. Information security responsibilities are addressed within Runlayer's internal project management processes as applicable.
2.4 Risk Assessments. Runlayer conducts formal risk assessments of the Information Security Program at least annually using a methodology aligned with industry-standard frameworks (e.g., NIST Special Publication 800-30). Risks are assessed based on likelihood and impact, and Runlayer maintains a documented risk register and applies documented risk treatment responses (including mitigation, acceptance, transfer, and avoidance) as appropriate.
2.5 Program Reviews. Runlayer reviews its Information Security Program and the associated policies and procedures at least annually and updates them as appropriate to address evolving information security risks.
2.6 Program Updates. Runlayer may update the Information Security Program from time to time, provided that any such updates will not materially diminish the overall level of security provided during the then-current Subscription Term.
3. HUMAN RESOURCES SECURITY
3.1 Confidentiality Obligations. All Runlayer personnel with access to Customer Data are required to sign confidentiality agreements prior to accessing Customer Data. Confidentiality obligations survive termination of employment or engagement.
3.2 Security Awareness Training. Runlayer provides security awareness training to all personnel at the time of hire and at least annually thereafter. Training covers Runlayer's information security policies, applicable data protection obligations, and recognition of common security threats.
3.3 Secure Development Training. Runlayer personnel involved in software development complete secure development training upon hire and at least annually thereafter. Training covers common application security risks, including injection attacks, cross-site scripting, authorization vulnerabilities, and the secure use of third-party libraries.
3.4 Subcontractor Personnel. Third parties with privileged access to Runlayer's production systems are required to undergo background checks or to provide evidence of background checks meeting equivalent standards, in each case to the extent permitted by applicable law.
3.5 Access Termination. Runlayer revokes physical and logical access for personnel within twenty-four (24) business hours of termination of employment, engagement, or role change resulting in loss of need for such access.
3.6 Performance Review. Runlayer's annual performance review process includes an assessment of personnel adherence to Runlayer's information security policies and code of conduct.
4. ASSET MANAGEMENT
4.1 Asset Inventory. Runlayer maintains an inventory of assets associated with information and information processing facilities used in the provision of the Services. Each asset is assigned to an individual or group that is accountable for the asset.
4.2 Acceptable Use. Runlayer maintains policies governing the acceptable use of assets, and personnel are required to comply with such policies.
4.3 Return of Assets. Runlayer requires personnel and external party users to return assets in their possession upon termination of employment, contract, or engagement. Upon receipt of the return, all data is permanently and unrecoverably destroyed and the asset is documented and tracked.
4.4 Data Classification. Runlayer classifies data based on legal requirements, value, criticality, and sensitivity to unauthorized disclosure or modification, and implements handling procedures appropriate to each classification.
4.5 Removable Media. Runlayer's operations do not rely on removable media. To the extent removable media is used by Runlayer personnel for incidental purposes, such use is governed by Runlayer's acceptable use and data classification policies.
4.6 Loss or Theft of Assets. Personnel are required to promptly report the loss or theft of any device or asset that may store or provide access to Customer Data or Runlayer information systems. Upon such report, Runlayer issues a remote wipe command to the affected device, which executes upon the device's next network connection.
5. ACCESS CONTROL
5.1 Access Control Policy. Runlayer maintains a written access control policy governing the provisioning, modification, and revocation of access to systems and information used in the provision of the Services.
5.2 Role-Based Access Control. Runlayer uses role-based access control (RBAC) as its primary access management model. Access rights are granted based on the principle of least privilege; permissions not expressly granted are denied by default.
5.3 Unique Credentials. Each individual with access to Runlayer's production systems is assigned unique access credentials. Generic, shared, or anonymous administrative accounts are prohibited. Personnel are trained on the prohibition against sharing credentials.
5.4 Multi-Factor Authentication. Runlayer requires multi-factor authentication for administrative and privileged access to production systems and for remote access to Runlayer's network.
5.5 Privileged Access. Privileged access rights are restricted, time-bound, and granted only for the duration of the specific task requiring such access. Privileged access is revoked promptly upon completion of the task.
5.6 Access Provisioning. Runlayer maintains a user access provisioning process to assign access rights across user types, systems, and services.
5.7 Access Reviews. Runlayer conducts documented reviews of user, administrator, and service account access rights at least quarterly.
5.8 Access Termination. Access rights of personnel and external party users are revoked promptly, and in any case within twenty-four (24) business hours, upon termination of employment, contract, or engagement.
5.9 Password Standards. Where Runlayer maintains password-based authentication, Runlayer enforces password complexity requirements (including minimum length and character composition), account lockout after a defined number of failed authentication attempts, and secure storage of passwords using a memory-hard or computationally hard one-way hash function with appropriate salting.
5.11 Session and Token Management. Sessions and tokens used to access Runlayer's production systems and the Services have finite lifetimes and secure termination procedures. Identity-provider sessions (e.g., via WorkOS/AuthKit) are validated on each request, invalid sessions are cleared, and logout expires session cookies. Token and session revocations are recorded in Runlayer's audit logs.
6. CRYPTOGRAPHY
6.1 Cryptography Policy. Runlayer maintains a written policy governing the use of cryptographic controls, including the use, protection, and lifecycle management of cryptographic keys.
6.2 Encryption in Transit. Runlayer encrypts Customer Data in transit over public networks using Transport Layer Security (TLS) version 1.2 or higher or equivalent industry-standard transport encryption.
6.3 Encryption at Rest. Runlayer encrypts Customer Data at rest using industry-standard encryption (e.g. AES-256).
6.4 Backup Encryption. Backups of Customer Data are encrypted and logically isolated from production data.
6.5 Endpoint Encryption. Runlayer requires full disk encryption on personnel endpoints used to access Customer Data, in accordance with Runlayer's cryptography policy.
7. PHYSICAL AND ENVIRONMENTAL SECURITY
7.1 Data Center Security. Customer Data is hosted in third-party cloud infrastructure provided by hyperscale cloud service providers. Runlayer relies on the physical and environmental security controls implemented by such providers, including access controls, monitoring, environmental safeguards, and physical security personnel. Runlayer assesses the physical security posture of its cloud infrastructure providers as part of its sub-processor due diligence process.
7.2 Corporate Facility Access. Runlayer's corporate facilities used to store or process production or sensitive internal data are protected by access control systems with per-person access logging.
7.3 Monitoring. Runlayer's corporate facilities used to store or process production or sensitive internal data are monitored by camera systems and intrusion detection systems.
7.4 Visitor Management. Visitors to Runlayer's corporate facilities are escorted by Runlayer personnel and are not granted unaccompanied access to facilities used to store or process production or sensitive internal data.
7.5 Loading and Delivery Areas. Where feasible, loading and delivery areas at Runlayer's corporate facilities are controlled and isolated from areas used for information processing.
8. OPERATIONS SECURITY
8.1 Change Management. Runlayer maintains a formal change management process for changes to the organization, business processes, information processing facilities, and systems that affect information security or the provision of the Services. Changes to production systems are reviewed, approved, and documented in accordance with this process.
8.2 Separation of Environments. Runlayer separates its development, testing, and production environments to reduce the risk of unauthorized access to, or unintended changes affecting, the production environment. Customer Data is not used in Runlayer's development or testing environments; where Customer Data is used for testing purposes, such data is scrubbed of sensitive information where feasible.
8.3 Vulnerability Management. Runlayer conducts vulnerability scanning of its public-facing production systems at least quarterly. Runlayer prioritizes vulnerability remediation based on severity, including by reference to industry-standard severity scoring (e.g., the Common Vulnerability Scoring System version 3 (CVSSv3)). Runlayer's target timeframes for vulnerability remediation are: critical and high-severity vulnerabilities within thirty (30) days of identification; medium-severity vulnerabilities within sixty (60) days; and low-severity vulnerabilities within ninety (90) days.
8.4 Penetration Testing. Runlayer engages a qualified third party to conduct annual penetration testing of its production systems. Penetration testing is conducted in accordance with industry-standard methodologies (e.g., the OWASP Testing Guide and the Penetration Testing Execution Standard (PTES)). Upon Customer's written request (no more than once per twelve (12) month period), Runlayer will provide a summary of its most recent penetration test, including scope, material findings, and remediation status, under the confidentiality obligations of the Agreement. Raw scan results, detailed penetration test outputs, and other sensitive security information are excluded from this commitment.
8.5 Malicious Code Protection. Runlayer's software development processes and production environment are designed to protect against the introduction of malicious code, including through code review, dependency scanning, and other controls aligned with industry-standard secure development practices (e.g., the OWASP Top 10 and SANS Top 25 Software Errors).
8.6 Logging and Monitoring. Runlayer logs and monitors access to production systems and Customer Data, including privileged administrative actions. Logs capture sufficient detail to attribute logged actions to the responsible actor and to support security investigation and review. Logs are protected against tampering and unauthorized access and are retained for a minimum of thirty (30) days.
8.7 System Hardening. Runlayer configures and maintains its production systems in alignment with industry-standard hardening benchmarks (e.g., CIS Benchmarks and NIST Guidelines), including the removal or disabling of unnecessary default accounts, the changing of vendor default credentials prior to deployment, and the application of security patches in accordance with Section 8.3.
8.8 File Integrity Monitoring. Runlayer's production systems are configured to monitor and alert on suspicious changes to critical system files where feasible.
8.9 Clock Synchronization. Runlayer synchronizes the clocks of its production systems to reputable network time sources.
8.10 Endpoint Protection. Runlayer requires anti-malware protection on personnel endpoints used to access Runlayer's production systems or Customer Data, and configures such protection to receive automatic updates and to detect, prevent, or quarantine common forms of malicious software.
9. NETWORK SECURITY
9.1 Network Segmentation. Runlayer segments its production network to limit access to authorized hosts and users and to restrict traversal between network segments to that which is required for the provision of the Services.
9.2 Perimeter Protection. Runlayer maintains firewalls and other network perimeter controls to restrict unauthorized network traffic to and from its production environment.
9.3 Intrusion Detection. Runlayer maintains intrusion detection and/or intrusion prevention controls designed to identify anomalous or unauthorized activity affecting its production environment.
9.4 Remote Access. Remote access to Runlayer's production environment is restricted to authorized personnel, requires multi-factor authentication, and is conducted over encrypted channels (e.g., TLS, SSH, or VPN). Management access to production systems from the public Internet is restricted to trusted sources.
9.5 Network Monitoring. Runlayer relies on continuous network monitoring provided by its cloud infrastructure provider and maintains an on-call rotation responsible for responding to security events affecting its production environment.
9.6 Public-Facing Servers. Publicly accessible servers are placed in a separate, isolated network segment.
9.7 Denial-of-Service and Application-Layer Protection. Runlayer maintains protections against distributed denial-of-service (DDoS) attacks and common application-layer threats targeting its production environment, including through its cloud infrastructure providers' native protection services.
10. SYSTEM ACQUISITION, DEVELOPMENT, AND MAINTENANCE
10.1 Secure Development Practices. Runlayer maintains written policies governing the secure development, deployment, and maintenance of the Services. Information security requirements are incorporated into Runlayer's software development lifecycle.
10.2 Application Security Testing. Runlayer conducts application security testing, including static application security testing (SAST), dynamic application security testing (DAST), and software composition analysis (SCA), in accordance with industry-standard practices (e.g., the OWASP Application Security Verification Standard).
10.3 Secure Engineering Principles. Runlayer applies industry-standard secure engineering principles in the design, development, and maintenance of the Services, including principles addressing input validation, output encoding, authentication, session management, access control, and protection against common application vulnerabilities.
10.4 Software Vulnerability Management. Runlayer provides updates and patches to address security vulnerabilities in the Services in accordance with a continuous delivery model and severity-based prioritization. For Services deployed on Customer-controlled infrastructure, Customer is responsible for the timely application of updates and patches made available by Runlayer.
10.5 Outsourced Development. To the extent Runlayer engages third parties to perform software development on behalf of Runlayer, such engagements are subject to Runlayer's sub-processor due diligence process and applicable information security obligations.
11. SUBPROCESSOR DUE DILIGENCE
11.1 Due Diligence. Runlayer conducts due diligence on its subprocessors to assess their security and privacy practices, with such due diligence calibrated to the nature, sensitivity, and volume of Customer Data such subprocessor will access or Process.
11.2 Security Requirements. Runlayer's agreements with subprocessors that access or Process Customer Data require such subprocessors to implement and maintain ISA appropriate to the nature of the Processing.
11.3 Cloud Infrastructure Providers. For hyperscale cloud infrastructure providers, Runlayer relies on the security commitments, certifications, and attestations made generally available by such providers to their enterprise customers.
11.4 Engagement and Notification. The engagement of subprocessors, including customer notification of changes to the subprocessor list, is governed by the DPA.
12. SECURITY INCIDENT RESPONSE
12.1 Incident Response Program. Runlayer maintains a written Security Incident response program, including documented policies and procedures for the identification, containment, investigation, eradication, recovery, and post-incident review of Security Incidents.
12.2 Incident Response Team. Runlayer maintains an incident response team responsible for executing the security incident response program. Members of the incident response team receive role-appropriate training.
12.3 Investigation. In the event of a Security Incident, Runlayer will reasonably investigate the cause and circumstances of the Security Incident, take reasonable steps to contain and mitigate its impact, and take appropriate remediation actions.
12.4 Evidence Handling. Runlayer collects and preserves evidence concerning Security Incidents in accordance with industry-standard practices to support investigation and, where applicable, regulatory or law enforcement engagement.
12.5 Documentation. Runlayer documents Security Incidents and the response actions taken, and retains such documentation in accordance with Runlayer's record retention standards.
12.6 Customer Notification. Customer notification of Security Incidents is governed by the DPA.
12.7 Incident Response Tooling. Runlayer's incident response program is supported by industry-standard security tooling, including endpoint detection and response (EDR) tooling deployed across personnel endpoints, cloud-native security monitoring services (e.g., AWS GuardDuty, AWS Security Hub, AWS CloudTrail), and software composition analysis and container scanning tooling. Specific tooling may be updated from time to time in accordance with Section 2.6 (Program Updates).
12.8 Plan Testing. Runlayer reviews and tests its Security Incident response program at least annually. Findings and lessons learned from testing activities are documented to inform improvements to the program.
13. BUSINESS CONTINUITY AND DISASTER RECOVERY
13.1 Business Continuity and Disaster Recovery Plans. Runlayer maintains documented business continuity and disaster recovery plans designed to ensure the continued availability and resilience of the Services in the event of a significant disruption.
13.2 Recovery Objectives. For Runlayer's core production Services hosted on hyperscale cloud infrastructure, Runlayer maintains a recovery time objective (RTO) of two (2) hours and a recovery point objective (RPO) of fifteen (15) minutes, in each case based on the availability commitments of Runlayer's cloud infrastructure provider.
13.3 Backups. Runlayer performs regular encrypted backups of production systems using managed backup services provided by its cloud infrastructure providers, with logical separation, access controls, and lifecycle policies aligned with Runlayer's internal access control policies. Customer is responsible for backup, archival, and retention of Customer Data.
13.4 Testing. Runlayer tests its business continuity and disaster recovery plans, including backup restoration procedures, at least annually.
13.5 Plan Review and Updates. Runlayer reviews and updates its business continuity and disaster recovery plans at least annually.
13.6 Workforce Continuity. Runlayer's business continuity plan provides for personnel to perform their roles from alternative locations in the event Runlayer's corporate facilities become unavailable.
13.7 Scope. The Services do not include customer-facing data backup, archival, or data restoration services. The commitments in this Section 13 relate to Runlayer's internal operations and platform resiliency.
14. AUDIT AND COMPLIANCE
14.1 SOC 2 Type II. Runlayer maintains SOC 2 Type II certification covering the systems used to provide the Services. Runlayer engages a qualified independent auditor to conduct its SOC 2 Type II examination annually.
14.2 Audit Rights. Customer audit rights, including the provision of SOC 2 Type II reports and other audit-related information, are governed by the DPA.
15. DATA RETURN AND DELETION
15.1 Return and Deletion. Customer's rights and Runlayer's obligations regarding the return and deletion of Customer Data upon expiration or termination of the Agreement are governed by the DPA.
15.2 Secure Deletion Standard. Runlayer applies secure deletion practices designed to render deleted Customer Data unrecoverable, including through the use of cryptographic controls in accordance with this ISA.
16. CHANGES TO ISA
16.1 Updates. Runlayer may update This ISA from time to time to address evolving security threats, technologies, regulatory requirements, or operational practices. Runlayer will not make changes that materially diminish the overall level of security provided under This ISA during the then-current Subscription Term.
16.2 Notice of Material Changes. Runlayer will provide Customer with at least thirty (30) days advance notice of material changes to This ISA, except where a shorter notice period is required to (a) respond to an emergent security threat or vulnerability, (b) comply with Applicable Law, or (c) address a change made by a sub-processor outside Runlayer's reasonable control. Notice may be provided through Runlayer's customer notification mechanisms, including by updating the version of This ISA referenced in the Agreement.