Data stays in the European Union
The database is in Ireland. No transfer to the United States or any other third country. We do not rely on the EU-US Data Privacy Framework, because we do not need to.
Client isolation is in the database, not the app
Every client’s data is separated by rules the database engine enforces. Even if someone bypassed the entire application, they would see only the data they are entitled to.
An activity log that cannot be altered
Every change to a production leaves a record: who, what and when. Records cannot be edited or deleted — the lock applies to our own service accounts too. That is why the post-show report is evidence rather than a note.
We do not track and we do not trade data
No advertising, no marketing cookies, no behavioural analytics. Typefaces are served from our own server, so the browser never connects to Google. We do not use client data to train AI models.
Where the data lives.
| Layer | Location |
|---|---|
| Database | Ireland (EU) |
| Error monitoring | Germany (Frankfurt) |
| Backups | The same EU region as the database |
| Transfer outside the EU | No — with the single exception below |
Push notifications — the single exception. To reach a phone, a notification passes through the operating system vendor’s push service. The payload is encrypted from our server to the device; the intermediary has no means of reading it. A message notification does not carry the message — the phone shows the channel and the production. Notifications can be switched off.
Who can see what.
Roles that mirror the production
Producer, show director, team leader, crew. Each role reaches what its function requires, and the limits are enforced in the database.
Script and technical notes stay in the editor
Team leaders and crew never see them.
Department channels are private from the producer
A deliberate product decision, not an oversight.
Crew links are revocable and expire
Individually or for a whole department, and on their own thirty days after a production wraps.
Two-factor authentication
TOTP with backup codes, enforced on irreversible operations: password change, disabling 2FA, account deletion.
A sign-in log the user can read
Type, IP address, browser, time.
Encryption.
| Layer | Control |
|---|---|
| In transit | TLS on all connections |
| At rest | AES-256 at the infrastructure provider |
| Passwords | Irreversible hashes only — plaintext passwords are never stored |
| Push notifications | Server-to-device encryption |
| Browser | HSTS, protection against embedding in third-party pages, referrer policy, device permission restrictions |
Continuity.
Backups with point-in-time recovery
A production can go ahead without the system
The rundown, the schedule and the crew lists print at any time, as PDF or XLSX. In a gallery, paper always works.
The console survives a network loss
It keeps counting, says plainly that it lost the connection, and returns to the correct time when the connection comes back.
Your data, and your rights.
Export
Self-service, in the account panel, including the messages you wrote.
Account deletion
Self-service, with a thirty-day window to change your mind.
Certifications, plainly.
We hold no SOC 2 or ISO 27001 certification of our own. We say so directly rather than leaving it out.
Our infrastructure is certified. The database, the compute and the hosting layers hold SOC 2 Type II and ISO/IEC 27001, and they carry the layer where most technical risk arises.
Reporting problems.
Found a vulnerability?
security@liverun.io. We take no legal action over good-faith reports, provided the research did not access other clients’ data and did not disrupt the service.
We never ask for your password. Not by e-mail, not in production chat, not by phone. If a “sign in again” link appears in a production chat, it is not us. Do not open it, tell the producer, and write to security@liverun.io.
This matters most for crew, who enter by link and may assume that any link in this place is safe.