Legal
Security
Last updated: September 8, 2026
Runars (ARS Technologies Inc.) protects customer data with layered controls across our Canadian infrastructure. This page describes our security practices, where data lives, who we rely on, and how to reach our security team.
1. Data residency
All customer content — prompts, completions, uploaded files, request logs, account records, and billing records — is stored and processed in Canadian data centres in Montreal and Calgary. We do not transfer customer content outside Canada for processing.
2. Infrastructure
- Compute for inference runs on our Canadian GPU Cloud across two Canadian data centres.
- Application and database services run in the Supabase Canada (Central) region.
- Environments are logically isolated per customer organization, with least-privilege access controls.
3. Encryption
- In transit: TLS 1.2+ for all API and dashboard traffic.
- At rest: encryption at the storage layer for databases, object storage, and backups.
- Secrets such as API keys are stored hashed or encrypted and are never displayed in full after creation.
- API keys should be stored by customers as secrets. If a key is compromised, rotate or revoke it from the dashboard immediately.
4. Access controls
Administrative access follows least privilege and is protected by multi-factor authentication. Within customer organizations, access is role based (owner, admin, member) and enforced at the database layer.
5. Monitoring and incident response
Platform health and security events are monitored continuously. In the event of a security incident affecting your data, we will investigate, contain, notify affected customers, and meet all Canadian legal notification obligations, including PIPEDA breach reporting where a real risk of significant harm exists.
6. Sub-processors
- Supabase — authentication, application database, and file storage (Canada region).
- Helcim — payment processing (Canada).
- Resend — transactional email delivery.
We vet sub-processors before engagement and contractually require equivalent data protection commitments.
7. Responsible disclosure
We welcome reports from the security community. If you believe you have found a vulnerability, email security@runars.ca with details. We ask that you:
- Give us a reasonable window to remediate before public disclosure.
- Avoid privacy violations, degradation of service, or data destruction while investigating.
- Only test against accounts you own or control.
We commit to acknowledging reports promptly and will not pursue action against good-faith research that follows these guidelines.
8. Related policies
See also our Privacy Policy and Terms of Service.