Trust

Security at RunLite

RunLite hosts businesses’ websites and carries their enquiries. This page lists the protections in place today, in plain terms. We don’t claim certifications we haven’t earned.

Infrastructure

AWS in Mumbai, served over HTTPS

RunLite runs on Amazon Web Services in the Mumbai region (ap-south-1). Site files are kept in private Amazon S3 storage that only our CloudFront distributions can read, through Origin Access Control, and are encrypted at rest. Every page is served over HTTPS; plain HTTP is redirected.

Data location

Stored in India

Site files and our database, which holds accounts and form submissions, are in AWS’s Mumbai region. Pages are cached at CloudFront locations worldwide so they load quickly everywhere. Every service that processes data for us is listed in our Privacy Policy.

Isolation

Customer sites on their own domain

Sites go live on {subdomain}.runlitehost.com, a separate domain from runlite.in, so code on a hosted site can’t read or set cookies for the dashboard or its sign-in. Every hosted site is served with HSTS, nosniff and referrer-policy headers.

Accounts

Verified sign-in, and notice of new connections

Every account signs in with Google or a one-time code sent to its email, so each one has a proven email address from the start. AI tools connect through OAuth on RunLite’s own consent screen, and we email you the first time a new app is connected to your account.

API keys

Shown once, stored as a hash

Dashboard API keys are shown once, when you create them. We keep only a SHA-256 hash and a short prefix so you can tell them apart, and you can revoke any key from the dashboard at any time.

Forms

Spam protection without a third-party CAPTCHA

Every form RunLite generates has a hidden honeypot field and an ALTCHA proof-of-work challenge served by our own API, so visitors are never sent to another company to prove they’re human. Submissions are kept for 90 days by default, then deleted automatically.

Abuse

Every deploy is checked

Before a deploy goes live, its files are checked for signs of phishing and malware. Likely phishing is refused, and anything doubtful is flagged for a person to review. Only static web files can be published, and a runlitehost.com page may not ask for passwords, card details, one-time codes, PINs or wallet phrases.

Anyone can report a site, and we review every report, usually within 24 hours.

Reliability

Built not to take sites down

Deploys are atomic: every file goes live, or none does. The last 20 published versions of each site are kept, so the dashboard can roll back in one click. Going over a plan’s limit never takes a live site down. This website, the dashboard, the API, the MCP server and a hosted site are checked every five minutes, with an alarm on any failure.

Payments

We never see card details

Payments go through Razorpay. Card and UPI details are entered with Razorpay and never reach RunLite’s servers.

Reporting a vulnerability

If you’ve found a security problem in RunLite itself, email support@runlite.in with the subject “Security report” and enough detail for us to reproduce it. Please don’t access other people’s data, degrade the service for others, or contact our users while you investigate. We’ll reply, keep you updated, and tell you when it’s fixed.

Our security.txt lists the same contact. To report a site hosted on RunLite rather than RunLite itself, use Report abuse.