company
runnerhut is now SOC 2 Type 2
We completed our SOC 2 Type 2 audit covering security, availability and confidentiality.
Jess Okonkwo · Co-founder · 2026-06-24 · 3 min read
We have completed a SOC 2 Type 2 audit covering a twelve-month observation period. The report is available under NDA.
The distinction between Type 1 and Type 2 is worth knowing when you evaluate any vendor: Type 1 attests that controls existed on a single day. Type 2 attests that they operated effectively over a period. Ask which one you are being shown.
- Trust services criteria: security, availability, confidentiality
- Twelve-month observation period
- Annual third-party penetration test, summary available under NDA
- GDPR DPA with published sub-processors
Your next build could be twice as fast, at half the price
Start free. Migrating away is the same one line, and we publish that diff too.
Related
CI when your teammates are agentsAI coding agents push far more often than humans. Here is how that changes pipeline design and cost control.Why we publish instructions for leavingEvery migration page on this site includes the diff to migrate back off us. Here is the reasoning.What we learned running a million CI jobsQueue time, cache behaviour, right-sizing and the failure modes that only appear at scale.Stop retrying flaky testsAutomatic retries convert a real bug into an intermittent one, and train your team to distrust every failure.