Security
Persistent logins are serious.here's the proof
Exactly how we handle sessions, secrets, isolation and audits — no hand-waving.
Envelope encryption
Browser sessions and MCP credentials are encrypted with a unique AES-256-GCM data key per record. Data keys are wrapped by a master key that lives only in the deployment environment — never in the database. Plain secrets are never written to disk or logs.
Isolation
Every connected account runs in its own browser context. Flight execution is scoped to a single tenant, and every database query is filtered by user.
Human-in-the-loop
Write actions can require approval before they execute. Domain allowlists constrain where agents navigate, and page content is treated as data — never as instructions.
Auditability
Every agent action, approval and admin operation is written to an append-only audit log with actor, target and timestamp. Run timelines include screenshots for browser steps.
Reporting
Report vulnerabilities to security@runpilots.com. We acknowledge within 24 hours and will not pursue good-faith researchers.
Ready when you are
Security you can audit
Every run keeps step logs, screenshots, cost and outcome. Export it, audit it, trust it.
7-day refund · Cancel anytime · No API keys · Encrypted by default