Effective: May 10, 2026
Summary
Runstamp is designed around a local-first package model. Your source code, document definitions, and generated outputs stay in your environment unless you send them to a hosted Runstamp feature, license service, support channel, or integration. Commercial licensing is designed to avoid embedding signing secrets in customer-side code; license certificates may be verified locally using public-key cryptography.
1. Security boundary
Runstamp packages may run on your developer machine, build server, CI/CD system, or production environment. You control those environments. We do not receive your source code, generated documents, document contents, or build artifacts from local or CI package execution unless you transmit them to us.
Hosted Runstamp features, account portals, license services, support channels, and enterprise services are Runstamp-controlled systems and are covered by the Privacy Policy, DPA, and Subprocessors page.
2. License security
Hosted Runstamp access uses API keys. Contracted enterprise deployments may additionally use signed offline entitlement certificates; the intended security model is:
- license certificates are signed by Runstamp-controlled signing keys;
- customer-side verification uses public-key verification, not embedded signing secrets;
- private signing material is not distributed to customers;
- hosted API status, revocation, or entitlement updates are checked online;
- leaked or abused API keys may be revoked or rotated.
Customers are responsible for protecting API keys, offline certificates, CI secrets, and deployment secrets. Do not commit them to public repositories or expose them in client-side code where unauthorized parties can reuse them. The Apache-2.0 local format packages do not require a hosted API key.
3. Package and dependency security
Runstamp packages are distributed through the public npm registry and source repositories where identified. Customers should:
- pin versions or use lockfiles for reproducible builds;
- review dependency changes before upgrades;
- restrict CI secrets to the minimum required scope;
- use trusted registries and verify package names to avoid typosquatting;
- monitor their own dependency and supply-chain risk.
Where feasible, we will document material package changes, security fixes, and migration guidance for Commercial Components.
4. Hosted systems safeguards
For Runstamp hosted systems, we maintain safeguards designed to protect account, license, support, and hosted Customer Content data, including:
- TLS for data in transit;
- encryption at rest through hosting and storage providers where supported;
- role-based access controls;
- least-privilege administrative access;
- multi-factor authentication for administrative systems where supported;
- logging and monitoring of security-relevant events;
- Cloudflare or equivalent network protection where enabled;
- Sentry or equivalent error monitoring where enabled;
- vulnerability and dependency monitoring;
- incident response procedures;
- subprocessor contractual controls.
5. Customer responsibilities
You are responsible for:
- securing your repositories, license keys, CI/CD systems, deployment environments, and generated outputs;
- deciding what source materials and personal data to process with Runstamp;
- avoiding secrets and regulated data in support attachments unless necessary and authorized;
- reviewing generated outputs before use;
- managing access for employees, contractors, and collaborators;
- complying with applicable security, privacy, and export-control obligations.
6. Hosted feature data
If you use hosted rendering, cloud compilation, playgrounds, template hosting, or enterprise services, data you submit may be processed in Runstamp systems and by subprocessors listed on the Subprocessors page. The product UI, Order Form, or documentation should identify retention and export behavior for each hosted feature.
7. Incident response
If we become aware of a security incident affecting your account, license, hosted Customer Content, or Customer Personal Data, we will investigate, contain, remediate, and notify affected customers as required by law and the DPA.
8. Vulnerability reporting
Send vulnerability reports to security@runstamp.com. Include:
- affected URL, package, API, or system;
- reproduction steps;
- potential impact;
- whether any data was accessed;
- your contact information.
Do not access other customers’ data, degrade the Service, run destructive tests, or disclose vulnerabilities publicly before we have had a reasonable opportunity to remediate.
9. Compliance status
Unless a current trust page or signed Order Form says otherwise, Runstamp does not claim SOC 2, ISO 27001, HIPAA, PCI DSS service-provider, FedRAMP, or similar certification. The SOC 2 program is IN PROGRESS/planned; the independent audit and report have not been completed or obtained. Paddle handles payment-card processing as merchant of record. See the Enterprise Security Kit for the current questionnaire summary, offline-license model, audit-log coverage, and deployment boundaries.
10. Contact
Security: security@runstamp.com
Privacy: privacy@runstamp.com
