SupportRunnerTrustSystem status

SECURITY POSTURE

Trust should be visible before an agent takes action.

SupportRunner is being built around explicit authority, tenant boundaries, safe release gates, and evidence that shows what changed. We publish what exists and label what is still in progress.

Current postureSandbox-ready

Public and evaluation boundaries are active. Production action controls and enterprise identity remain gated.

Control inventory

What is enforced today

Reviewed August 2026

Encrypted transport

TLS-only production domains with HSTS and secure browser headers.

Available

Scoped sessions

HTTP-only workspace sessions are checked server-side for each evaluation read and write.

Available

Tenant-aware persistence

Workspace records use opaque identifiers and scoped storage access.

Available

Inspectable evidence

Consequential actions are designed around immutable versions, authorization, idempotency, and verification.

In progress

Data boundaries

Each surface gets only what it needs

Public site

No customer records

Marketing and product education remain separate from workspace data.

Evaluation workspace

Sandbox by default

External writes stay disabled until a connector and explicit grant are configured.

Public API

Discovery only

The unauthenticated API exposes health and public-safe topology, not tenant resources.

Status surface

Sanitized projection

Availability checks publish no internal topology, credentials, or customer data.

Claims we do not make

No borrowed certifications. No vague “enterprise-grade” badge.

SupportRunner does not currently claim SOC 2, ISO 27001, HIPAA eligibility, PCI scope, or production SSO/SCIM. Those controls will move from roadmap to published evidence only after they are implemented and independently supported.