Encrypted transport
TLS-only production domains with HSTS and secure browser headers.
SECURITY POSTURE
SupportRunner is being built around explicit authority, tenant boundaries, safe release gates, and evidence that shows what changed. We publish what exists and label what is still in progress.
Public and evaluation boundaries are active. Production action controls and enterprise identity remain gated.
Control inventory
TLS-only production domains with HSTS and secure browser headers.
HTTP-only workspace sessions are checked server-side for each evaluation read and write.
Workspace records use opaque identifiers and scoped storage access.
Consequential actions are designed around immutable versions, authorization, idempotency, and verification.
Data boundaries
Marketing and product education remain separate from workspace data.
External writes stay disabled until a connector and explicit grant are configured.
The unauthenticated API exposes health and public-safe topology, not tenant resources.
Availability checks publish no internal topology, credentials, or customer data.
Claims we do not make
SupportRunner does not currently claim SOC 2, ISO 27001, HIPAA eligibility, PCI scope, or production SSO/SCIM. Those controls will move from roadmap to published evidence only after they are implemented and independently supported.