Procurement-ready answers, in one place.
Your CISO, HR Director, and procurement team need to defend the choice of Rosterna in five minutes. This page is for them.
Hosted in Saudi Arabia. Built for KSA data residency.
Rosterna runs on managed cloud infrastructure with encryption at rest, per-organization data isolation, and database-level tenant isolation (RLS) enforced in production. Customer data is hosted inside the Kingdom of Saudi Arabia (Riyadh), on in-Kingdom cloud infrastructure.
A real, licensed Saudi entity
Rosterna is operated by a Saudi-registered business licensed in the Kingdom of Saudi Arabia under Commercial Registration (CR) 7053617655 (ZATCA Tax ID 3146208814). You are contracting with a registered, verifiable Saudi entity — not an anonymous app.
Registered in SDAIA's National Register for Personal Data Protection
The establishment operating Rosterna is officially registered as a data controller in the National Register for Personal Data Protection at SDAIA (the Saudi Data & AI Authority) — registration certificate no. 3260007328, status Active. Built to the Saudi PDPL: a documented breach-notification procedure, data-subject access requests on request, and data minimization by design.
DPO assessment — completed with SDAIA
As part of our National Register filing, SDAIA's official assessment concluded that appointing a dedicated Data Protection Officer is not mandatory for our processing profile — no sensitive data and no systematic monitoring. Privacy requests go directly to the founder: hello@rosterna.com with subject 'Privacy'.
NCA controls mapping
We map our security controls to the National Cybersecurity Authority Essential Cybersecurity Controls (ECC-1:2018). A controls summary is available to your security architects on request.
Type 1 — Q4 2027 target
SOC 2 Type 1 audit with a major Saudi audit firm targeted for Q4 2027. Type 2 to follow within 18 months.
Data Processing Agreement
Our Data Processing Agreement — aligned with PDPL controller–processor obligations, with the sub-processor list and in-Kingdom residency terms — is published for procurement teams to read directly.
Row-level security, enforced in production
Every one of Rosterna's 33 tenant tables enforces PostgreSQL row-level security (RLS). The API connects through a dedicated, non-superuser database role that cannot bypass it — verified live, not just configured. Cross-tenant reads and writes are blocked at the database layer, not only in application code.
Encryption in transit & at rest
TLS 1.3 in transit and AES-256 encryption at rest on managed infrastructure. Column-level encryption for sensitive fields like National ID / Iqama, and customer-managed keys (BYOK), are on our Enterprise roadmap.
Immutable audit log
Every state change is recorded in an immutable audit log with full before/after detail and actor attribution. SIEM export (JSON / CEF / LEEF) and cryptographic hash-chaining are on the roadmap.
Found a vulnerability?
We work with researchers in good faith. Disclose privately at the address below; we acknowledge within 48 hours and credit you on our security page if you wish.
security@rosterna.com