All guides
Encryption
Browser sessions and MCP credentials are sealed with envelope encryption: a unique AES-256-GCM key per record, wrapped by a master key held in the deployment environment. Plain secrets are never written to disk or logs.
Isolation
Each connected account runs in its own isolated browser context. Flight processes are scoped to one tenant; every database query is filtered by user.
Monitoring & audit
Every agent action, approval and admin operation is written to an append-only audit log with actor, target and timestamp.
Your responsibilities
You are responsible for the accounts you connect and for complying with each platform’s terms. Report vulnerabilities to security@runpilots.com — we do not run a public bug bounty yet, but we respond fast.
Ready when you are
Put this guide to work
Connect an account and run your first scheduled flight tonight.
7-day refund · Cancel anytime · No API keys · Encrypted by default