SECURITY & GDPR
Data protection by design
DryRun is a pre-deployment simulation service. The current product has no adapter capable of taking live action in customer, payment or support systems.
Roles and DPA
The customer is normally the data controller and DryRun the data processor for uploaded case data. A data processing agreement, including Article 28 terms and documented instructions, is available for pilot customers before personal data is uploaded.
Infrastructure and sub-processors
Cloudflare provides hosting, edge delivery and D1 database storage. OpenAI provides the sign-in identity flow; DryRun does not receive account passwords. The deterministic simulation engine does not send case data to an external AI-model provider. The current sub-processor list is reviewed before each paid pilot.
Storage, retention and deletion
Workspace data is access-scoped server-side. Pilot datasets are deleted on request or within 60 days after a pilot ends unless an ongoing agreement defines another period. Account deletion removes raw case content and personal fields while retaining minimised audit evidence where necessary for security, legal claims and accountability.
Operational controls
Changes are traceable through audit events. Reports use access-controlled links. Logs must not contain raw uploads, email bodies, tokens or credentials. The outreach tracker is an internal, access-restricted business record and is not published with the website. Security incidents should be reported to peter@dryrunops.com.
Current limitations
No independent security certification or external penetration-test claim is made on this page. Data residency, deletion schedules and any additional sub-processors must be confirmed in the customer DPA.