RunWhatMatters / Boston
Home
HubSpot Process Awards Contact
(617) 401-7650
Home/ Security
Legal

Security & Compliance

Last updated September 9, 2026. What we hold, what's in progress, and how we handle your code and data during an engagement.

HIPAA Ready

Pre-cleared Business Associate Agreement (BAA) template, executed per engagement for healthcare clients.

NDA / DPA Ready

Mutual NDA executed in under 24 hours; Data Processing Addendum available for any engagement handling regulated personal data.

SOC 2 Type II In progress

Formal audit not yet complete. Ask your scoping engineer for current target timeline before relying on this for a compliance decision.

ISO 27001 In progress

Certification not yet complete. Ask your scoping engineer for current status.

1. Data handling

During an engagement, we access only what a signed SOW scopes: source repositories, staging/production infrastructure needed to build and ship, and any business data explicitly required for the work. Access is credentialed per-engineer, not shared, and revoked at engagement end unless a support retainer is in place.

2. IP ownership and assignment

Unless the SOW states otherwise, work product you pay for is yours — code, architecture documents, and designs assign to you on payment. We don't retain a license to reuse your proprietary business logic in other engagements. Reusable internal tooling we bring to every engagement (not built specifically for you) remains ours.

3. Source code and repo handover

At handoff (see our delivery process), you receive full repository ownership, infrastructure access, and recorded architecture walkthroughs — not a document dump. If an engagement ends early, in-progress code in your repository is yours as of the last invoiced milestone.

4. Subprocessors

We use a small, vetted set of vendors to run our own business (site hosting/CDN, CRM, calendar booking, analytics) — none of which touch client source code or production credentials unless explicitly scoped into an engagement (e.g., a client's own cloud provider). A current subprocessor list is available on request.

5. Incident response

If we identify a security issue in something we built or maintain for you, we notify the named technical contact on the engagement as soon as it's confirmed — not after root-cause analysis is complete — and follow with a written summary once resolved.

6. Vendor risk / due diligence

For enterprise procurement and vendor-risk reviews, we can provide: engagement references, our current compliance status (above), our subprocessor list, and answers to a standard security questionnaire. Email hello@runwhatmatters.com with "vendor risk review" in the subject line.

Available Q4 2026

Let's build what comes next.

Book a 30-minute working session with a RunWhatMatters principal. Bring an idea, a roadmap, or a hard problem. We'll bring the whiteboard.

Start a Project (617) 401-7650
RunWhatMatters

Boston's full-stack enterprise software engineering studio. Seven disciplines. One studio. Engineered in Boston, MA since 2018.

SOC 2 Type II
HIPAA-ready
ISO 27001

Services

  • Enterprise Software Development
  • Web Development
  • Mobile Development
  • Cloud-Based Software Solutions

More

  • AI and ML Services
  • Digital Transformation
  • Legacy System Modernization
  • HubSpot Integration
  • Contact

Boston Studio

  • 101 Federal Street, Suite 1900
  • Boston, MA 02110
  • (617) 401-7650
  • hello@runwhatmatters.com
Mon–Fri · 9:00 AM – 6:00 PM ET
© 2026 RunWhatMatters, Inc. · Engineered in Boston, Massachusetts.
Privacy Terms Security Accessibility