Security & Privacy

Efficient Automation with Clear Boundaries

Runavelo is designed for real business systems. Workflows run on the user's computer, an enterprise server, or another customer-designated environment by default. Customers manage business accounts, passwords, verification codes, and execution data under their own access policies.

Runavelo security and privacy
Local Execution Workflows can run on a user's Windows computer, a server, or an execution environment inside the corporate network.
Customer-managed Credentials Users configure and maintain business accounts, passwords, and verification codes in their own environment.
Traceable Logs Execution status and failed-step records support investigation and review.
Private Deployment Enterprise editions can support internal networks, offline activation, and dedicated runners.
Data Boundaries

What Remains in the Customer Environment

Automation interacts with business systems, so execution environments, account permissions, and log retention are central to the security design.

Business-system Data

Orders, customer records, admin pages, exported files, and other business data can be processed on customer computers, servers, or internal networks. Enterprise delivery can integrate with existing directories, databases, and access policies.

Accounts and Credentials

Customers maintain platform accounts, passwords, verification codes, browser environments, and login sessions. For sensitive systems, use dedicated execution accounts, least privilege, and regular credential rotation.

Workflows and Logs

Workflow files, runtime logs, error screenshots, and execution results can remain local under the delivery plan for troubleshooting, auditing, and ongoing optimization.

Enterprise Deployment

Validate First, Then Scale from PoC to Production

For enterprise use, start with a frequent, rules-based workflow that a person can verify. Once validated, expand gradually to additional systems and accounts.

1. Map the Workflow Identify system entry points, account permissions, data sources, exception paths, and manual review points.
2. Validate the PoC Use a small number of accounts or sample records to validate stability, execution time, and exception handling.
3. Configure Access Configure runner accounts, file directories, execution machines, log locations, and notifications for the customer's environment.
4. Launch and Maintain Retain logs, screenshots, and version history so workflows can be diagnosed and updated when platform pages change.
Recommendations

Which Processes Are Good Candidates for Automation?

Good Candidates

Rules-based processes such as repeated logins, data transfer, spreadsheet processing, order synchronization, bulk queries, report downloads, and notifications.

Use with Care

Processes involving fund transfers, irreversible submissions, sensitive approvals, or tightly controlled platforms should include human confirmation, allowlists, and permission isolation.

Limitations

We do not promise to bypass third-party risk controls or guarantee that every page will remain stable indefinitely. Page redesigns, CAPTCHAs, and platform restrictions may require workflow updates.

Frequently Asked Questions

Questions Enterprises Commonly Ask Before Launch

Are account credentials uploaded to Runavelo servers?

Users configure and maintain business-system accounts, passwords, verification codes, and sessions on their own computers, servers, or enterprise environments. We recommend dedicated runner accounts with least-privilege access for enterprise deployments.

Where is workflow execution data stored?

Execution data such as orders, spreadsheets, screenshots, and logs can be stored in local directories according to the deployment plan. For sensitive data, the customer should define retention periods and access permissions.

Can it be deployed on an enterprise intranet or in an offline environment?

The Enterprise edition can be evaluated for intranet deployment, offline activation, dedicated runners, and customer-managed execution machines. The final design depends on system entry points, network policies, account permissions, and operational requirements.

What if a redesign, CAPTCHA, or risk control causes a workflow to fail?

Automation does not promise to bypass third-party risk controls. When a redesign, CAPTCHA, dialog, or platform restriction interrupts a workflow, logs and screenshots can identify the failed step for human review or workflow adjustment.

Which processes should not be fully automated?

High-risk actions such as fund transfers, irreversible submissions, sensitive approvals, and customer-data changes should not run entirely unattended. Add human confirmation, allowlists, permission isolation, and audit trails.