Trust

How Prudence is operated and secured

What this page is

Runciter maintains this page to answer recurring security and privacy questions about the service. It describes the controls the product has today. It is not a certification, an audit report, or independent verification.

Shared responsibility

Prudence provides the register, the access controls and the audit trail. The customer remains the controller of the personal data it enters, and remains responsible for the accuracy of its records, for the members it admits to the organisation, and for the decisions those records document.

Runciter acts as a processor for the content placed in Prudence and processes it only to provide the service, on the documented instructions of the customer, as Article 28 requires.

Hosting

The application and its database are hosted in the European Union. Backups remain within the same region.

Access and authentication

Access requires an authenticated account. Sign-in supports email and password, and Google sign-in. Every account belongs to one or more organisations, and membership grants access to a register.

Roles separate what a data protection officer, a contributor and a reader can do. Business unit scoping can further narrow what a member sees within an organisation.

Tenant isolation

Records are isolated per organisation at the database level using row level security, so a query can only ever return rows belonging to an organisation the requesting account is a member of. Isolation is enforced by the database rather than by application code alone.

Audit trail

Field changes, status transitions, links and record creation are written to an append-only audit trail with the acting account and a timestamp. Audit entries cannot be edited or deleted from the interface.

What does not belong in Prudence

Prudence is a register of processing operations, not a store of the personal data being processed. Consent records and data subject requests are built around pseudonymous references for that reason. Names, contact details and case content of individual data subjects belong in the source system, not in the register.

Reporting a vulnerability

Report a suspected security issue to Runciter before disclosing it publicly. Each report receives an assessment and a remediation timeline.