Security

The questions your
security desk will ask.

Answered here, before anyone has to send an e-mail to find out. Specifically, and without generalities — this holds the schedules, rosters and team conversations of production crews, which is a client’s operational data.

Data stays in the European Union

The database is in Ireland. No transfer to the United States or any other third country. We do not rely on the EU-US Data Privacy Framework, because we do not need to.

Client isolation is in the database, not the app

Every client’s data is separated by rules the database engine enforces. Even if someone bypassed the entire application, they would see only the data they are entitled to.

An activity log that cannot be altered

Every change to a production leaves a record: who, what and when. Records cannot be edited or deleted — the lock applies to our own service accounts too. That is why the post-show report is evidence rather than a note.

We do not track and we do not trade data

No advertising, no marketing cookies, no behavioural analytics. Typefaces are served from our own server, so the browser never connects to Google. We do not use client data to train AI models.

Where the data lives.

LayerLocation
DatabaseIreland (EU)
Error monitoringGermany (Frankfurt)
BackupsThe same EU region as the database
Transfer outside the EUNo — with the single exception below

Push notifications — the single exception. To reach a phone, a notification passes through the operating system vendor’s push service. The payload is encrypted from our server to the device; the intermediary has no means of reading it. A message notification does not carry the message — the phone shows the channel and the production. Notifications can be switched off.

Who can see what.

Roles that mirror the production

Producer, show director, team leader, crew. Each role reaches what its function requires, and the limits are enforced in the database.

Script and technical notes stay in the editor

Team leaders and crew never see them.

Department channels are private from the producer

A deliberate product decision, not an oversight.

Crew links are revocable and expire

Individually or for a whole department, and on their own thirty days after a production wraps.

Two-factor authentication

TOTP with backup codes, enforced on irreversible operations: password change, disabling 2FA, account deletion.

A sign-in log the user can read

Type, IP address, browser, time.

Encryption.

LayerControl
In transitTLS on all connections
At restAES-256 at the infrastructure provider
PasswordsIrreversible hashes only — plaintext passwords are never stored
Push notificationsServer-to-device encryption
BrowserHSTS, protection against embedding in third-party pages, referrer policy, device permission restrictions

Continuity.

Backups with point-in-time recovery

A production can go ahead without the system

The rundown, the schedule and the crew lists print at any time, as PDF or XLSX. In a gallery, paper always works.

The console survives a network loss

It keeps counting, says plainly that it lost the connection, and returns to the correct time when the connection comes back.

Your data, and your rights.

Export

Self-service, in the account panel, including the messages you wrote.

Account deletion

Self-service, with a thirty-day window to change your mind.

Certifications, plainly.

We hold no SOC 2 or ISO 27001 certification of our own. We say so directly rather than leaving it out.

Our infrastructure is certified. The database, the compute and the hosting layers hold SOC 2 Type II and ISO/IEC 27001, and they carry the layer where most technical risk arises.

Reporting problems.

Found a vulnerability?

security@liverun.io. We take no legal action over good-faith reports, provided the research did not access other clients’ data and did not disrupt the service.

We never ask for your password. Not by e-mail, not in production chat, not by phone. If a “sign in again” link appears in a production chat, it is not us. Do not open it, tell the producer, and write to security@liverun.io.

This matters most for crew, who enter by link and may assume that any link in this place is safe.

Security questions: security@liverun.io · Everything else: team@liverun.io