RunPod limits its security responsibility to physical infrastructure including hardware, hypervisors, networking equipment, and facilities. Users are contractually responsible for data encryption at rest and in transit, VM guest configuration, OS patching, application security, firewall rules, load balancer settings, object and block storage configuration, and IP and DNS settings.
This analysis describes what RunPod's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the contractual boundary of RunPod's security obligations and assigns a defined set of operational security responsibilities to users. Enterprise customers must assess whether their internal security controls and incident response procedures address the user-side obligations enumerated in this clause, particularly where applicable data protection law may impose independent obligations on the data controller.
The updated Terms of Service remove previous promotional language including referral bonuses (previously described as $5-$500 random credit bonuses) and product feature descriptions. The revised document now explicitly states it is a legally binding agreement between you and RunPod, Inc., with a last-updated date of March 24, 2026. No new restrictions or obligations are introduced by this change; the restructuring primarily formalizes the legal framework and eliminates marketing content that previously appeared within the terms document.
View change record →Under this clause, users are contractually responsible for encrypting data at rest and in transit, maintaining VM and OS security patches, configuring firewalls and storage access controls, and ensuring backup integrity. RunPod's contractual security obligation is limited to the physical and virtual infrastructure layer below the user's compute instance.
Cross-platform context
See how other platforms handle Shared Responsibility Model for Data Security and similar clauses.
Compare across platforms →"You are responsible for ensuring all data (including Your Content) is secured with backups and encryption as required to meet applicable laws and industry standards. You acknowledge and agree that data privacy and information security is a shared responsibility between you and Runpod. Runpod is responsible for protecting the infrastructure that provides the Service to you. This infrastructure is composed of the hardware, software, networking, facilities, storage, load balancing units, switches, virtual machine hypervisors, and other related networking equipment, including any installation, maintenance, and support thereof. For the avoidance of doubt, the Service does not include your applications or Your Content. Under this shared responsibility model, you are responsible for protecting all data (including Your Content) both at rest and in transit, virtual machine guests, operating system(s) (including updates and security patches), associated application software, as well as security configuration of the Service provided by Runpod, including but not limited to firewall, load balancer, object storage, block storage, IP and DNS configuration.Excerpt from RunPod's Terms of Service
REGULATORY LANDSCAPE: The shared responsibility model interacts with GDPR Article 32 obligations requiring appropriate technical and organizational measures to secure personal data, CCPA security obligations for businesses processing California resident data, and HIPAA Security Rule …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes the contractual boundary of RunPod's security obligations and assigns a defined set of operational security responsibilities to users. Enterprise customers must assess whether their internal security controls and incident response procedures address the user-side obligations enumerated in this clause, particularly where applicable data protection law may impose independent obligations on the data controller.
Under this clause, users are contractually responsible for encrypting data at rest and in transit, maintaining VM and OS security patches, configuring firewalls and storage access controls, and ensuring backup integrity. RunPod's contractual security obligation is limited to the physical and virtual infrastructure layer below the user's compute instance.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by RunPod.