Trust Center

Procurement-ready answers, in one place.

Your CISO, HR Director, and procurement team need to defend the choice of Rosterna in five minutes. This page is for them.

Data residency

Hosted in Saudi Arabia. Built for KSA data residency.

Rosterna runs on managed cloud infrastructure with encryption at rest, per-organization data isolation, and database-level tenant isolation (RLS) enforced in production. Customer data is hosted inside the Kingdom of Saudi Arabia (Riyadh), on in-Kingdom cloud infrastructure.

Per-tenant isolationEncryption at restHosted in the Kingdom (Riyadh)
Registered business

A real, licensed Saudi entity

Rosterna is operated by a Saudi-registered business licensed in the Kingdom of Saudi Arabia under Commercial Registration (CR) 7053617655 (ZATCA Tax ID 3146208814). You are contracting with a registered, verifiable Saudi entity — not an anonymous app.

Licensed in KSA
PDPL

Personal Data Protection Law alignment

Built to the Saudi PDPL: a documented breach-notification procedure, data-subject access requests on request, and data minimization by design. SDAIA Data Controller registration is in progress — the registration ID will be published here once filed.

Breach procedureDSAR on requestRegistration in progress
Registration ID — coming soon
DPO

Named Data Protection Officer

A KSA-resident DPO is being appointed and will be named publicly here once formal designation is filed. Contact in the meantime: hello@rosterna.com with subject 'DPO'.

KSA-residentPublic listingDirect contact
Email DPO
ECC-1:2018

NCA controls mapping

We map our security controls to the National Cybersecurity Authority Essential Cybersecurity Controls (ECC-1:2018). A controls summary is available to your security architects on request.

ECC-aligned
Request matrix
SOC 2

Type 1 — Q4 2027 target

SOC 2 Type 1 audit with a major Saudi audit firm targeted for Q4 2027. Type 2 to follow within 18 months.

Roadmap published
View roadmap
DPA

Data Processing Agreement

Our Data Processing Agreement — aligned with PDPL controller–processor obligations, with the sub-processor list and in-Kingdom residency terms — is published for procurement teams to read directly.

Procurement-friendly
Read the DPA
Tenant isolation

Row-level security, enforced in production

Every one of Rosterna's 33 tenant tables enforces PostgreSQL row-level security (RLS). The API connects through a dedicated, non-superuser database role that cannot bypass it — verified live, not just configured. Cross-tenant reads and writes are blocked at the database layer, not only in application code.

RLS on 33/33 tablesNon-superuser DB roleEnforced at the DB layer
Encryption

Encryption in transit & at rest

TLS 1.3 in transit and AES-256 encryption at rest on managed infrastructure. Column-level encryption for sensitive fields like National ID / Iqama, and customer-managed keys (BYOK), are on our Enterprise roadmap.

AES-256 at restTLS 1.3BYOK — roadmap
Audit

Immutable audit log

Every state change is recorded in an immutable audit log with full before/after detail and actor attribution. SIEM export (JSON / CEF / LEEF) and cryptographic hash-chaining are on the roadmap.

Before/after captureActor attribution

Found a vulnerability?

We work with researchers in good faith. Disclose privately at the address below; we acknowledge within 48 hours and credit you on our security page if you wish.

security@rosterna.com