Trust & Security
Rostra holds evidence your business depends on, and personal data your clients trust you with. Here is exactly where it lives, who processes it, and the guarantees every workspace gets — in plain language.
Where your data lives
| Data | System | Region | Safeguards |
|---|---|---|---|
| All structured data (staff, sessions, bookings, evidence records) | Supabase (PostgreSQL) | Singapore (AWS ap-southeast-1) | Encrypted at rest (AES-256) and in transit (TLS 1.2+) |
| Proof photos & documents | Object storage | Singapore-served | Private buckets; time-limited signed URLs; org-scoped paths |
| Authentication (password hashes, sessions) | Supabase Auth | Singapore (AWS ap-southeast-1) | bcrypt hashing; TOTP 2FA available |
| Transactional email | Resend | Asia-Pacific (Tokyo) | Minimal payload: names, emails, session details only |
| Payments (when enabled) | Stripe | Global (PCI-DSS Level 1) | Card data never touches Rostra systems |
| Application compute | Vercel | Singapore (sin1) | Stateless functions; no customer data at rest |
This table is our subprocessor list. We will update it before adding any new processor.
Our commitments
Tenant isolation, enforced in the database
Every row of your data carries your organization’s identity, enforced by PostgreSQL row-level security — not just application code. Our automated test suite proves cross-tenant isolation on every table before any release ships.
Audit integrity by design
Delivery evidence is immutable once captured. Verification windows close cleanly — there is no mechanism, for staff, admins, or Rostra itself, to retroactively fabricate a check-in, edit a submitted checklist, or backdate evidence. Offline-synced events are timestamped at capture and flagged if they arrive late.
We never track people between sessions
Location is captured once, at check-in and check-out, against the venue’s tolerance. Rostra has no continuous tracking, no background location, and no location history outside session evidence.
Your data is yours, in every billing state
Full export is available at any time — including if your subscription lapses. A cancelled or read-only workspace keeps its data intact and exportable. We never hold data hostage.
Breach notification measured in hours
If a breach affects your data, we commit to notifying affected organizations without undue delay — hours, not days — with what we know, what we’ve done, and what you should do, consistent with Singapore PDPA guidance.
Least-privilege access
Client evidence portals are unguessable, revocable tokens scoped to a single programme. Staff cannot see pay rates that aren’t theirs, portal tokens, or other organizations. Platform-level support access is logged with a justification on every action.
Retention
Delivery evidence is retained while your workspace is active. Proof photos default to a 24-month retention window (configurable per organization) and are then permanently deleted. Deleted workspaces are purged after a 30-day grace period. Audit logs are append-only for the life of the workspace.
Questions, requests, disclosures
Data protection contact: dpo@rostrahq.com. We respond to access, correction, and deletion requests under Singapore's PDPA, and support our customers in meeting their own obligations to their clients.