Security & Trust

Built for the controls enterprise teams require

Roiva holds your initiatives, the credentials for the systems you connect, and what it syncs from them: totals, and records trimmed to the fields it needs. We treat all of it with the controls a finance team would expect.

What we do, end to end

Encryption

TLS 1.2+ for data in transit. AES-256 at rest for sensitive credentials. Database backups are encrypted at rest.

Authentication

Email + password with rate-limiting. Optional 2FA via authenticator app or SMS. SSO and SAML included in larger rollouts.

Authorization

Every request from your team needs an active membership in your account and can reach only your account's records, plus Roiva's read-only shared library of metrics and formulas. Access ends as soon as a member is removed or suspended. Role policies gate account settings, approvals, finance close and integration management. Fixed roles per account: Owner, Admin, and Member.

Audit log

Account-scoped audit trail of authentication, role changes, integration connections, value approvals, MCP tool calls, document opens, and admin actions. Available on paid plans.

AI providers

Anthropic Claude powers the in-app assistant. Your data is never used to train their models. See AI transparency below.

Hosting

Hosted on AWS in the United States. Application and background workers run in isolated containers behind a managed load balancer. Every uploaded file is scanned for malware on arrival, and one found to contain malware is never delivered.

What Roiva keeps from the systems you connect

A sync reads the records it needs, such as tickets, deals or bills, and saves only the fields the reference below lists for each kind. The rest is dropped, never stored: a ticket's subject and messages, a contact's email or phone, a customer's address, a calendar event's title and attendee emails. Roiva never reads a prompt or a response from an AI provider, and from Snowflake, Databricks and BigQuery it reads only billing and usage views, never your own tables.

What it keeps can still identify people, and the reference says where: deal and opportunity names, customer names on invoices and Stripe charges, free text such as a line description or an issue summary, and people by the platform's own ID. In your account, only Owners and Admins can open synced records.

It's kept while your account is, not on a schedule. Deleting a connection deletes its records, except a bill an allocation rule split, and deleting the account deletes everything. Database backups are kept for 7 days.

How we treat your data when AI is involved

Your data is never used to train AI models. Roiva uses Anthropic Claude to power the in-app assistant. Anthropic is configured with data-processing terms that prohibit training on your inputs. Only the minimum context required for an answer (initiative titles, metric summaries, ROI figures) is sent. Read the AI transparency statement for the full breakdown.
Your own AI assistants can read Roiva, and only read it. With MCP access (included on every paid plan), an account admin issues a token that lets Claude Code, Cursor or another MCP client answer questions from your account's initiatives, costs, approved value and ROI. It cannot change anything. Tokens are stored as a one-way SHA-256 digest and shown once, expire within a year, act with the issuing admin's membership, and stop working as soon as that admin is removed or the token is revoked. Every lookup the assistant makes is recorded in your audit log. The answers go to the assistant's AI provider under your own agreement with it: it is your tool, not a Roiva sub-processor.

Who else touches your data

The same list published in section 5 of the privacy policy, which is the authoritative version.

Sub-processor Purpose Data location
AWS Application hosting, database, file storage, job queue, outbound email United States
Stripe Payments and subscription billing United States / EU
Sentry Application error monitoring United States
Anthropic Assistant inference, initiative estimates, document analysis United States
PostHog Product and usage analytics United States
HubSpot Demo scheduling and assessment lead contact records United States
Google Analytics 4 Marketing-site analytics, consent-gated United States

Found a security issue? Tell us first.

Email security@roiva.ai with a description of the issue and the steps to reproduce it.

This covers roiva.ai, app.roiva.ai and Roiva's integrations, including the Roiva app for Slack.

  • We acknowledge every report within one business day.
  • We aim to ship a fix or mitigation for high-severity issues within seven calendar days.
  • Please give us the chance to fix an issue before you disclose it publicly.

Compliance and security reviews

Roiva's SOC 2 Type 2 program with Oneleet started on September 25, 2026. The examination covers the Security criteria of the AICPA Trust Services Criteria and includes a three-month observation period. The report will be issued by an independent CPA firm from Oneleet's partner network, and Oneleet manages the audit.

The same engagement includes a manual penetration test of the Roiva application every year, by an OSCE-certified tester working from the OWASP Top 10, ASVS and WSTG, with each finding retested once it's fixed.

There is no SOC 2 report yet. Until there is, write to us for Oneleet's engagement letter, a security questionnaire, a vendor risk review, or our latest sub-processor list, and we'll respond within one business day.

security@roiva.ai