Procurement-ready answers, in one place.
Your CISO, HR Director, and procurement team need to defend the choice of Rosterna in five minutes. This page is for them.
Hosted in Saudi Arabia. Built for KSA data residency.
Rosterna runs on managed cloud infrastructure with encryption at rest, per-organization data isolation, and database-level tenant isolation (RLS) enforced in production. Customer data is hosted inside the Kingdom of Saudi Arabia (Riyadh), on in-Kingdom cloud infrastructure.
A real, licensed Saudi entity
Rosterna is operated by a Saudi-registered business licensed in the Kingdom of Saudi Arabia under Commercial Registration (CR) 7053617655 (ZATCA Tax ID 3146208814). You are contracting with a registered, verifiable Saudi entity — not an anonymous app.
Personal Data Protection Law alignment
Built to the Saudi PDPL: a documented breach-notification procedure, data-subject access requests on request, and data minimization by design. SDAIA Data Controller registration is in progress — the registration ID will be published here once filed.
Named Data Protection Officer
A KSA-resident DPO is being appointed and will be named publicly here once formal designation is filed. Contact in the meantime: hello@rosterna.com with subject 'DPO'.
NCA controls mapping
We map our security controls to the National Cybersecurity Authority Essential Cybersecurity Controls (ECC-1:2018). A controls summary is available to your security architects on request.
Type 1 — Q4 2027 target
SOC 2 Type 1 audit with a major Saudi audit firm targeted for Q4 2027. Type 2 to follow within 18 months.
Data Processing Agreement
Our Data Processing Agreement — aligned with PDPL controller–processor obligations, with the sub-processor list and in-Kingdom residency terms — is published for procurement teams to read directly.
Row-level security, enforced in production
Every one of Rosterna's 33 tenant tables enforces PostgreSQL row-level security (RLS). The API connects through a dedicated, non-superuser database role that cannot bypass it — verified live, not just configured. Cross-tenant reads and writes are blocked at the database layer, not only in application code.
Encryption in transit & at rest
TLS 1.3 in transit and AES-256 encryption at rest on managed infrastructure. Column-level encryption for sensitive fields like National ID / Iqama, and customer-managed keys (BYOK), are on our Enterprise roadmap.
Immutable audit log
Every state change is recorded in an immutable audit log with full before/after detail and actor attribution. SIEM export (JSON / CEF / LEEF) and cryptographic hash-chaining are on the roadmap.
Found a vulnerability?
We work with researchers in good faith. Disclose privately at the address below; we acknowledge within 48 hours and credit you on our security page if you wish.
security@rosterna.com