Trust Center

Procurement-ready answers, in one place.

Your CISO, HR Director, and procurement team need to defend the choice of Rosterna in five minutes. This page is for them.

Data residency

Hosted in Saudi Arabia. Built for KSA data residency.

Rosterna runs on managed cloud infrastructure with encryption at rest, per-organization data isolation, and database-level tenant isolation (RLS) enforced in production. Customer data is hosted inside the Kingdom of Saudi Arabia (Riyadh), on in-Kingdom cloud infrastructure.

Per-tenant isolationEncryption at restHosted in the Kingdom (Riyadh)
Registered business

A real, licensed Saudi entity

Rosterna is operated by a Saudi-registered business licensed in the Kingdom of Saudi Arabia under Commercial Registration (CR) 7053617655 (ZATCA Tax ID 3146208814). You are contracting with a registered, verifiable Saudi entity — not an anonymous app.

Licensed in KSA
PDPL

Registered in SDAIA's National Register for Personal Data Protection

The establishment operating Rosterna is officially registered as a data controller in the National Register for Personal Data Protection at SDAIA (the Saudi Data & AI Authority) — registration certificate no. 3260007328, status Active. Built to the Saudi PDPL: a documented breach-notification procedure, data-subject access requests on request, and data minimization by design.

SDAIA registration no. 3260007328Breach procedureDSAR on request
Ask about PDPL
Privacy contact

DPO assessment — completed with SDAIA

As part of our National Register filing, SDAIA's official assessment concluded that appointing a dedicated Data Protection Officer is not mandatory for our processing profile — no sensitive data and no systematic monitoring. Privacy requests go directly to the founder: hello@rosterna.com with subject 'Privacy'.

SDAIA assessment completedFounder-direct contact
Email privacy contact
ECC-1:2018

NCA controls mapping

We map our security controls to the National Cybersecurity Authority Essential Cybersecurity Controls (ECC-1:2018). A controls summary is available to your security architects on request.

ECC-aligned
Request matrix
SOC 2

Type 1 — Q4 2027 target

SOC 2 Type 1 audit with a major Saudi audit firm targeted for Q4 2027. Type 2 to follow within 18 months.

Roadmap published
View roadmap
DPA

Data Processing Agreement

Our Data Processing Agreement — aligned with PDPL controller–processor obligations, with the sub-processor list and in-Kingdom residency terms — is published for procurement teams to read directly.

Procurement-friendly
Read the DPA
Tenant isolation

Row-level security, enforced in production

Every one of Rosterna's 33 tenant tables enforces PostgreSQL row-level security (RLS). The API connects through a dedicated, non-superuser database role that cannot bypass it — verified live, not just configured. Cross-tenant reads and writes are blocked at the database layer, not only in application code.

RLS on 33/33 tablesNon-superuser DB roleEnforced at the DB layer
Encryption

Encryption in transit & at rest

TLS 1.3 in transit and AES-256 encryption at rest on managed infrastructure. Column-level encryption for sensitive fields like National ID / Iqama, and customer-managed keys (BYOK), are on our Enterprise roadmap.

AES-256 at restTLS 1.3BYOK — roadmap
Audit

Immutable audit log

Every state change is recorded in an immutable audit log with full before/after detail and actor attribution. SIEM export (JSON / CEF / LEEF) and cryptographic hash-chaining are on the roadmap.

Before/after captureActor attribution

Found a vulnerability?

We work with researchers in good faith. Disclose privately at the address below; we acknowledge within 48 hours and credit you on our security page if you wish.

security@rosterna.com