Monitoring that can survive examination.
A monitoring capability is durable only if it can withstand examination by counsel, regulators, and the people it covers. This page is the framework we bring to the first scoping meeting; the deployed system enforces it technically.
Consent that is written, informed, and technically enforced.
Everyone in scope is covered by explicit written consent stating what is monitored, from which sources, for what purposes, and who sees findings — drafted with your counsel, integrated with employment policy, and renewed on a defined cycle. The consent registry gates collection programmatically: a person or source outside a current written scope cannot be collected from.
Where employee consent alone cannot lawfully carry a program — under the GDPR and in works-council jurisdictions it rarely can — the deployment rests on the lawful bases, impact assessments, and consultations your counsel directs.
Sanctioned channels and public material, defined in writing.
Runite reads two categories of source, both defined in a written scope your counsel approves: sanctioned firm channels — communications archives, trade and order data, code repositories, HR systems — and publicly available material, where no personal accounts are accessed, no private groups are joined, and no pretexts are used.
Personal devices and accounts are outside scope unless firm policy brings one in explicitly, as with a firm-issued phone.
One standard from analyst to executive.
One written standard applies at every level of seniority, and findings route to the governance body your policy designates in advance — they cannot be redirected around any individual or intercepted by the person they concern. A program that executives trust with their own conduct is the only kind employees will trust with theirs.
The system keeps a complete record of its own use.
- Compartmentalized access. Access is role-based, least-privilege, and case-scoped: investigators see the case in front of them, not a browsable feed of the firm.
- Append-only audit ledger. Every query, view, export, and configuration change is logged immutably — including by administrators and by Runite.
- Documented disposition. Every case file carries a named owner and a documented outcome, so the record shows supervision exercised rather than knowledge accumulated. Privilege and retention are structured with counsel before collection begins.
- Examinable on demand. The ledger and scope documents are structured for review by counsel, audit, and regulators without preparation.
- Retention by policy. Material persists exactly as long as your written policy provides, then is destroyed on the record.
Programs we decline to build.
These exclusions are standing policy rather than negotiating positions.
- Covert programs. If a capability cannot be disclosed to the people it covers, we will not build it.
- Surveillance of protected activity. Lawful organizing, whistleblower and anonymous reporting channels, and lawful off-duty conduct are categorically outside scope.
- Collection outside the written scope. We do not access personal accounts, use pretexts, or purchase private data about employees.
- Automated verdicts. The platform produces evidence for human judgment; no action, accusation, or score comes from the system alone.
- Secret sentiment dossiers. Sentiment analysis is aggregated and disclosed; we do not build hidden per-person files.
- Data resale of any kind. Client data trains no shared models and reaches no other client.
Designed to support the obligations you already carry.
Runite is designed to strengthen how firms meet the supervisory, surveillance, and recordkeeping obligations they already carry under the SEC, FINRA, FCA, and EU regimes, and to produce documentation that stands up when examined. We are an engineering firm rather than a law firm; every deployment is structured with the client's own counsel.
Bring this framework to your counsel, and then bring us both to the table.
Briefings are held under NDA with principals — compliance, legal, operating leadership, founders.
Discuss the framework with us