Trust Center

Procurement-ready answers, in one place.

Your CISO, HR Director, and procurement team need to defend the choice of Rosterna in five minutes. This page is for them.

Data residency

Your data lives in Riyadh.

All Rosterna multi-tenant infrastructure runs in AWS me-central-1 (Riyadh). No Saudi PII leaves the Kingdom. Backups stay in-region. The CST Cloud Computing Regulatory Framework Level 2 alignment statement is downloadable below.

AWS RiyadhCST Level 2No cross-border transfer
PDPL

Personal Data Protection Law compliance

Registered Data Controller. DPIA on file. 72-hour breach notification procedure. DSAR self-serve for any data subject. Cross-border transfers blocked unless SDAIA-approved.

Article 30 audit trailDSAR endpoint72-hour notification
Registration ID — coming soon
DPO

Named Data Protection Officer

A KSA-resident DPO is being appointed and will be named publicly here once formal designation is filed. Contact in the meantime: hello@rosterna.sa with subject 'DPO'.

KSA-residentPublic listingDirect contact
Email DPO
ECC-1:2018

NCA controls matrix

Controls mapped 1:1 to the National Cybersecurity Authority Essential Cybersecurity Controls. Downloadable as PDF + JSON for your security architects.

Mapped 1:1
Request matrix
SOC 2

Type 1 — Q4 2027 target

SOC 2 Type 1 audit with a major Saudi audit firm targeted for Q4 2027. Type 2 to follow within 18 months.

Roadmap published
View roadmap
DPA

Pre-signed Data Processing Addendum

A pre-signed DPA is ready for download — no back-and-forth required for procurement teams. Aligns with PDPL controller-processor obligations.

Procurement-friendly
Request DPA
Encryption

AES-256 + BYOK on Compliance Pro

AES-256 at rest, TLS 1.3 in transit. National ID, Iqama number, and salary fields encrypted at the column level. Enterprise customers can bring their own KEK in AWS KMS.

AES-256TLS 1.3BYOK
Audit

Hash-chained immutable log

Every state change writes an immutable event with SHA-256 hash chain. Exportable to your SIEM in JSON, CEF, or LEEF. Tampering breaks the chain — verifiable.

JSON · CEF · LEEFTamper-evident

Found a vulnerability?

We work with researchers in good faith. Disclose privately at the address below; we acknowledge within 48 hours and credit you on our security page if you wish.

security@rosterna.sa