← All docs

Security & privacy

How Run Pilots protects accounts, credentials and data.

All guides

Encryption

Browser sessions and MCP credentials are sealed with envelope encryption: a unique AES-256-GCM key per record, wrapped by a master key held in the deployment environment. Plain secrets are never written to disk or logs.

Isolation

Each connected account runs in its own isolated browser context. Flight processes are scoped to one tenant; every database query is filtered by user.

Monitoring & audit

Every agent action, approval and admin operation is written to an append-only audit log with actor, target and timestamp.

Your responsibilities

You are responsible for the accounts you connect and for complying with each platform’s terms. Report vulnerabilities to security@runpilots.com — we do not run a public bug bounty yet, but we respond fast.

Ready when you are

Put this guide to work

Connect an account and run your first scheduled flight tonight.

7-day refund · Cancel anytime · No API keys · Encrypted by default