Security

Know What Runs Locally and What Goes Online

Workflow execution normally occurs on the Windows computer or execution environment you control. Account, payment, publishing, update, and AI-assisted features use online services when you choose them. Review these boundaries before using sensitive data.

Runavelo security and privacy
Local Execution Workflows can run on a user's Windows computer, a server, or an execution environment inside the corporate network.
Customer-managed Credentials Credentials normally remain in the environment you control unless you place them in content sent to an online feature.
Traceable Logs Execution status and failed-step records support investigation and review.
Private Deployment Business deployments can be evaluated for internal networks, offline activation, and dedicated runners.
Data Boundaries

What Normally Remains in Your Environment

Local automation data remains under your control unless a workflow or online feature is configured to transmit, upload, or publish it.

Business-system Data

Orders, customer records, admin pages, exported files, and other business data can be processed on customer computers, servers, or internal networks. Enterprise delivery can integrate with existing directories, databases, and access policies.

Accounts and Credentials

Customers maintain platform accounts, passwords, verification codes, browser environments, and login sessions. For sensitive systems, use dedicated execution accounts, least privilege, and regular credential rotation.

Workflows and Logs

Workflow files, runtime logs, error screenshots, and execution results normally remain local. Applications or files you intentionally publish are uploaded to online storage.

Online Services

When Data Leaves the Local Environment

Runavelo transmits only the information needed for the online feature you request, but you remain responsible for reviewing the content you choose to send.

Accounts and Payments

Email verification, sessions, plans, entitlement balances, and order status are processed by Runavelo services. Stripe processes payment details during checkout.

AI Assistance

Prompts and the workflow, documentation, file, or error context you select are sent to the AI provider configured for the conversation. Do not include passwords, API keys, or regulated data unless you have reviewed that provider's controls.

Publishing and Updates

Applications you choose to publish are uploaded to managed object storage. Software-update checks transmit the edition and version information needed to determine available updates.

Enterprise Deployment

Validate First, Then Scale from PoC to Production

For enterprise use, start with a frequent, rules-based workflow that a person can verify. Once validated, expand gradually to additional systems and accounts.

1. Map the Workflow Identify system entry points, account permissions, data sources, exception paths, and manual review points.
2. Validate the PoC Use a small number of accounts or sample records to validate stability, execution time, and exception handling.
3. Configure Access Configure runner accounts, file directories, execution machines, log locations, and notifications for the customer's environment.
4. Launch and Maintain Retain logs, screenshots, and version history so workflows can be diagnosed and updated when platform pages change.
Recommendations

Which Processes Are Good Candidates for Automation?

Good Candidates

Rules-based processes such as repeated logins, data transfer, spreadsheet processing, order synchronization, bulk queries, report downloads, and notifications.

Use with Care

Processes involving fund transfers, irreversible submissions, sensitive approvals, or tightly controlled platforms should include human confirmation, allowlists, and permission isolation.

Limitations

We do not promise to bypass third-party risk controls or guarantee that every page will remain stable indefinitely. Page redesigns, CAPTCHAs, and platform restrictions may require workflow updates.

Frequently Asked Questions

Common Questions Before Running an Automation

Are workflow credentials uploaded to Runavelo servers?

Workflow credentials normally remain on the execution computer. Runavelo does not require you to send them to an AI provider or publish them. However, any secret included in a prompt, selected workflow context, uploaded file, log, or published application can be transmitted with that content. Use dedicated accounts, least privilege, and secret-free prompts.

Where is workflow execution data stored?

Execution data such as orders, spreadsheets, screenshots, and logs is normally stored in local directories. Content you intentionally publish or send through an online feature follows the storage and retention rules for that feature and its provider.

Can it be deployed on an enterprise intranet or in an offline environment?

The Enterprise edition can be evaluated for intranet deployment, offline activation, dedicated runners, and customer-managed execution machines. The final design depends on system entry points, network policies, account permissions, and operational requirements.

What if a redesign, CAPTCHA, or risk control causes a workflow to fail?

Automation does not promise to bypass third-party risk controls. When a redesign, CAPTCHA, dialog, or platform restriction interrupts a workflow, logs and screenshots can identify the failed step for human review or workflow adjustment.

Which processes should not be fully automated?

High-risk actions such as fund transfers, irreversible submissions, sensitive approvals, and customer-data changes should not run entirely unattended. Add human confirmation, allowlists, permission isolation, and audit trails.