Security
Your club’s data stays your club’s data.
Boards should ask hard questions about a small vendor. Here’s how RunUp is built — in plain language — and where we’re still early.
Tenant isolation
Every row belongs to exactly one club. Queries are club-scoped — there is no path to another club’s data via a hand-crafted URL.
Roles per club, per person
Your role at Flying Pigs does not grant access at another club. Permissions are evaluated on every request for that club membership.
Payments stay in your club
A payment to your club settles to your club’s Stripe Connect account — including for members who also fly elsewhere.
Export is a feature, not leverage
CSV and PDF export is available during the relationship and after. We don’t hold your records hostage to keep the subscription.
Financial records are immutable
Finalised invoices snapshot membership level and tax rate. Voids are recorded — lines are not quietly deleted.
We never store your password
Authentication runs through a dedicated identity provider (Clerk). RunUp stores membership and ops data, not credentials.
Transport security
Traffic to RunUp is served over HTTPS. When the canonical marketing and app hosts are on the public DNS we operate, we intend to enforce HSTS (including preload where appropriate) so browsers refuse cleartext — the claim follows the hosts we control, not a temporary preview URL.
An honest maturity callout
RunUp is early. Flying Pigs Flight Club is customer #1 — the club that shaped the product. We will share an open-items list on request rather than pretend SOC 2 is already framed on the wall. Being early is discoverable; hiding it is how you lose a volunteer board’s trust.
Want the open-items list?
Book a demo and ask for it — or start a trial and export everything whenever you want.