Trust
Security at RunLite
RunLite hosts businesses’ websites and carries their enquiries. This page lists the protections in place today, in plain terms. We don’t claim certifications we haven’t earned.
- Infrastructure
AWS in Mumbai, served over HTTPS
RunLite runs on Amazon Web Services in the Mumbai region (ap-south-1). Site files are kept in private Amazon S3 storage that only our CloudFront distributions can read, through Origin Access Control, and are encrypted at rest. Every page is served over HTTPS; plain HTTP is redirected.
- Data location
Stored in India
Site files and our database, which holds accounts and form submissions, are in AWS’s Mumbai region. Pages are cached at CloudFront locations worldwide so they load quickly everywhere. Every service that processes data for us is listed in our Privacy Policy.
- Isolation
Customer sites on their own domain
Sites go live on
{subdomain}.runlitehost.com, a separate domain from runlite.in, so code on a hosted site can’t read or set cookies for the dashboard or its sign-in. Every hosted site is served with HSTS, nosniff and referrer-policy headers.- Accounts
Verified sign-in, and notice of new connections
Every account signs in with Google or a one-time code sent to its email, so each one has a proven email address from the start. AI tools connect through OAuth on RunLite’s own consent screen, and we email you the first time a new app is connected to your account.
- API keys
Shown once, stored as a hash
Dashboard API keys are shown once, when you create them. We keep only a SHA-256 hash and a short prefix so you can tell them apart, and you can revoke any key from the dashboard at any time.
- Forms
Spam protection without a third-party CAPTCHA
Every form RunLite generates has a hidden honeypot field and an ALTCHA proof-of-work challenge served by our own API, so visitors are never sent to another company to prove they’re human. Submissions are kept for 90 days by default, then deleted automatically.
- Abuse
Every deploy is checked
Before a deploy goes live, its files are checked for signs of phishing and malware. Likely phishing is refused, and anything doubtful is flagged for a person to review. Only static web files can be published, and a runlitehost.com page may not ask for passwords, card details, one-time codes, PINs or wallet phrases.
Anyone can report a site, and we review every report, usually within 24 hours.
- Reliability
Built not to take sites down
Deploys are atomic: every file goes live, or none does. The last 20 published versions of each site are kept, so the dashboard can roll back in one click. Going over a plan’s limit never takes a live site down. This website, the dashboard, the API, the MCP server and a hosted site are checked every five minutes, with an alarm on any failure.
- Payments
We never see card details
Payments go through Razorpay. Card and UPI details are entered with Razorpay and never reach RunLite’s servers.
Reporting a vulnerability
If you’ve found a security problem in RunLite itself, email support@runlite.in with the subject “Security report” and enough detail for us to reproduce it. Please don’t access other people’s data, degrade the service for others, or contact our users while you investigate. We’ll reply, keep you updated, and tell you when it’s fixed.
Our security.txt lists the same contact. To report a site hosted on RunLite rather than RunLite itself, use Report abuse.