Security at RunwaySync

Last updated: September 10, 2026

RunwaySync helps FBOs and airports manage operational information that matters to their day-to-day business. Protecting that information is an important part of how we design, build, and operate RunwaySync.

Our security approach focuses on protecting customer data, limiting access, separating production systems, maintaining recoverability, and continually improving our practices as RunwaySync grows.

Cloud Infrastructure

RunwaySync's production services are hosted on Amazon Web Services (AWS).

We maintain separate AWS environments for development and production to reduce the risk that development activities affect production systems or customer data.

Production database services are not directly accessible from the public internet. Network controls restrict access to production resources so that internal services are available only to application systems and authorized administrators that require access.

Security in the cloud is a shared responsibility. AWS is responsible for securing the underlying cloud infrastructure, while RunwaySync is responsible for securely configuring and operating the services, applications, access controls, and data within our environment.

Encryption and Data Protection

RunwaySync uses encryption to help protect production customer data in transit and at rest.

Data in Transit

Connections to RunwaySync applications and services are protected using HTTPS/TLS encryption. Connections to production database services are also configured to require encrypted connections.

Data at Rest

Production database storage is encrypted at rest using AWS encryption services. Production file and object storage used by RunwaySync is also protected using server-side encryption.

Sensitive Configuration

Sensitive application configuration and credentials are maintained using secure AWS-managed configuration capabilities rather than being intentionally stored in application source code.

Payment Information

Payments are processed through Stripe. RunwaySync does not store complete payment-card numbers.

Identity and Administrative Access

Administrative access to RunwaySync infrastructure is restricted to authorized personnel.

RunwaySync uses centralized AWS identity management and multi-factor authentication (MFA) for administrative cloud access.

Access permissions are assigned according to operational need, with the goal of limiting people and systems to the resources necessary to perform their functions.

AWS root credentials are protected and are not used for routine administration.

Environment and Network Separation

RunwaySync separates production and development environments to provide an additional boundary around production systems and customer information.

Network security controls are used to restrict communication between resources and to prevent direct public access to internal production database systems.

Application workloads receive only the infrastructure access necessary to perform their intended functions.

Application Security

RunwaySync incorporates security controls into the development, application, and deployment process.

These controls include:

  • authenticated access to protected application functionality;

  • authorization based on user access and role;

  • controls designed to restrict users to organizational information they are authorized to access;

  • secure management of application credentials and configuration;

  • controlled automated build and deployment processes; and

  • application and server logging to support troubleshooting, monitoring, and investigation.

We continue to evaluate and strengthen application security as the product and threat landscape evolve.

Backups and Recovery

RunwaySync maintains automated backups of production database information to support recovery from data loss or system failure.

RunwaySync has tested its recovery procedures to verify that production database backups can be successfully restored.

No backup system can eliminate every risk, but recoverability is treated as an important part of protecting customer operations.

Logging and Monitoring

RunwaySync maintains application and server logs that help us identify errors, investigate unexpected behavior, diagnose operational issues, and respond to potential security concerns.

Automated operational notifications are used to bring certain application errors and system conditions to our attention.

These systems do not represent a guarantee of continuous human monitoring. We continue to expand our monitoring and security capabilities as RunwaySync grows.

Service Providers

RunwaySync relies on established service providers for portions of our infrastructure and business operations.

Our primary cloud infrastructure is hosted by Amazon Web Services. Other providers support functions such as payment processing, communications, website operations, and business productivity.

We seek to limit service-provider access to information reasonably necessary for the services they perform on our behalf.

More information about our use of service providers and handling of personal information is available in our Privacy Policy.

Customer Data

As between RunwaySync and its customers, customers retain their ownership rights in the data they submit to RunwaySync.

RunwaySync processes Customer Data as necessary to provide, secure, maintain, and support the Services and as otherwise described in our Terms of Service and Privacy Policy.

RunwaySync does not sell Customer Data.

For additional information about data ownership, privacy, permitted data use, and our treatment of aggregated, de-identified, and AI-related data, please review our Privacy Policy and Terms of Service.

Security Incidents

If we become aware of a suspected security incident affecting RunwaySync systems or Customer Data, we will take reasonable steps appropriate to the circumstances to investigate the event, contain and remediate identified risks, and assess its impact.

Where notification is required by applicable law or an applicable customer agreement, we will provide the required notification to affected customers or individuals.

Responsible Security Reporting

We welcome good-faith reports of potential security vulnerabilities affecting RunwaySync.

If you believe you have discovered a security vulnerability, please contact:

security@runwaysync.com

Please include enough information for us to understand and reproduce the issue where reasonably possible.

When investigating a potential vulnerability, please do not access, modify, destroy, download, or disclose another person's or organization's data; intentionally disrupt RunwaySync services; conduct social-engineering attacks; attempt to gain persistent unauthorized access; or publicly disclose a potential vulnerability before RunwaySync has had a reasonable opportunity to investigate and address it.

Reporting a vulnerability does not create eligibility for payment or establish a bug-bounty program.

Security Resources

Looking for additional technical detail?

Security Overview

A concise customer security brief covering RunwaySync infrastructure, administrative access, network security, encryption, authentication, backup and recovery, monitoring, and current assurance status.

Download Security Overview →

Security FAQ

Detailed answers to common security and technology questions for IT, security, procurement, and vendor-risk reviews.

Download Security FAQ →

The information on this page is intended to remain the most current public description of RunwaySync's security practices. Downloadable security documents provide additional point-in-time detail and identify the date on which they were last reviewed.

Your Role in Security

Security is a shared responsibility.

Organizations and users can help protect their RunwaySync accounts by protecting account credentials, using unique and strong passwords, limiting accounts to authorized users, promptly removing access when it is no longer required, protecting devices used to access RunwaySync, and notifying us if unauthorized account activity is suspected.

Security Questions

If your organization is evaluating RunwaySync and has questions about our security practices, infrastructure, data protection, or needs assistance with a security questionnaire, please contact:

security@runwaysync.com

We are happy to provide additional information appropriate to your organization's security review.

For general product or account support, contact:

support@runwaysync.com

This page provides a general overview of RunwaySync's current security practices. It is not a certification, warranty, service-level agreement, or guarantee that security incidents cannot occur. Contractual commitments regarding RunwaySync services are governed by the applicable Terms of Service and any written agreement between RunwaySync and the customer.

Ready to see RunwaySync at your FBO?

See how your team can manage service requests, fuel activity, forms, and daily operational work from one connected system.

No credit card required.

Built for FBO teams.

Powerfully Simple

Ready to see RunwaySync at your FBO?

See how your team can manage service requests, fuel activity, forms, and daily operational work from one connected system.

No credit card required.

Powerfully Simple

Built for FBO teams.

Ready to simplify your operations?

See how your team can manage service requests, fuel activity, forms, and daily operational work from one connected system.

No credit card required.

Powerfully Simple

Built for FBO teams.