SECURITY DOCUMENT
SECURITY OVERVIEW
A concise enterprise view of the current RUNSHIFT security and data boundary.
DATA FLOW
Source CRM or structured import → read-only/source adapter → canonical deal/evidence model → recurring mechanics → operating rules → controlled changes → tests and history.
SOURCE ACCESS
HubSpot V1 is read-only. Optional source capabilities increase evidence coverage but do not change the engine or authorize CRM write-back.
AUTHORIZATION AND TENANT BOUNDARY
Workspace-scoped access controls, active membership and role/authority checks separate customer data and privileged actions.
CREDENTIAL HANDLING
OAuth credentials remain server-side and are encrypted at rest within the connector's credential store. Tokens are not returned to browser state.
DATA MINIMIZATION
RUNSHIFT does not require email bodies, call transcripts, unrestricted CRM field access, employee scores or psychological profiles to operate the current product.
AI BOUNDARY
Server-side model calls are limited to candidate-generation/planning functions and receive explicitly constructed structural context. OAuth token material is excluded from that context.
PRIVACY OPERATIONS
Authorized workspace export and deletion workflows are implemented. See the Privacy Notice and DPA / AVV.
AUDIT AND RECOVERY
Security/admin audit is separate from Operating Memory. Backup and restore follow a documented runbook; production evidence is verified for the deployed environment before customer onboarding.