What this page is
Runciter maintains this page to answer recurring security and privacy questions about the service. It describes the controls the product has today. It is not a certification, an audit report, or independent verification.
Trust
Runciter maintains this page to answer recurring security and privacy questions about the service. It describes the controls the product has today. It is not a certification, an audit report, or independent verification.
Prudence provides the register, the access controls and the audit trail. The customer remains the controller of the personal data it enters, and remains responsible for the accuracy of its records, for the members it admits to the organisation, and for the decisions those records document.
Runciter acts as a processor for the content placed in Prudence and processes it only to provide the service, on the documented instructions of the customer, as Article 28 requires.
The application and its database are hosted in the European Union. Backups remain within the same region.
Access requires an authenticated account. Sign-in supports email and password, and Google sign-in. Every account belongs to one or more organisations, and membership grants access to a register.
Roles separate what a data protection officer, a contributor and a reader can do. Business unit scoping can further narrow what a member sees within an organisation.
Records are isolated per organisation at the database level using row level security, so a query can only ever return rows belonging to an organisation the requesting account is a member of. Isolation is enforced by the database rather than by application code alone.
Field changes, status transitions, links and record creation are written to an append-only audit trail with the acting account and a timestamp. Audit entries cannot be edited or deleted from the interface.
Prudence is a register of processing operations, not a store of the personal data being processed. Consent records and data subject requests are built around pseudonymous references for that reason. Names, contact details and case content of individual data subjects belong in the source system, not in the register.
Report a suspected security issue to Runciter before disclosing it publicly. Each report receives an assessment and a remediation timeline.