Security

Persistent logins are serious.here's the proof

Exactly how we handle sessions, secrets, isolation and audits — no hand-waving.

AES-256-GCM vaultApprovalsAppend-only audit log
1

Envelope encryption

Browser sessions and MCP credentials are encrypted with a unique AES-256-GCM data key per record. Data keys are wrapped by a master key that lives only in the deployment environment — never in the database. Plain secrets are never written to disk or logs.

2

Isolation

Every connected account runs in its own browser context. Flight execution is scoped to a single tenant, and every database query is filtered by user.

3

Human-in-the-loop

Write actions can require approval before they execute. Domain allowlists constrain where agents navigate, and page content is treated as data — never as instructions.

4

Auditability

Every agent action, approval and admin operation is written to an append-only audit log with actor, target and timestamp. Run timelines include screenshots for browser steps.

5

Reporting

Report vulnerabilities to security@runpilots.com. We acknowledge within 24 hours and will not pursue good-faith researchers.

Ready when you are

Security you can audit

Every run keeps step logs, screenshots, cost and outcome. Export it, audit it, trust it.

7-day refund · Cancel anytime · No API keys · Encrypted by default