Legal · Updated January 2026
Security
Infrastructure
Runko runs on hardened cloud infrastructure with network protections and compliance controls from our providers. Workloads run in isolated, per-service sandboxes.
Encryption
All traffic is encrypted in transit with TLS. Data at rest — including databases, persistent disks and secrets — is encrypted using provider-managed keys.
Secrets
Environment variables marked as secrets are encrypted and only decrypted inside your running workload. They are never printed in logs or exposed in the dashboard after creation.
Access & isolation
Each service runs on a private network by default. Public exposure is opt-in per service. Internal traffic between your services never leaves the private network.
Reporting a vulnerability
Found something? Email security@runko.arovi.app. We investigate every report and operate a responsible-disclosure program.
This document is a product demonstration and not legal advice.