Built for the controls enterprise teams require
Roiva handles initiative metadata, integration credentials, and aggregated metric data — and we treat all of it with the controls a finance team would expect.
Pillars
What we do, end to end
Encryption
TLS 1.2+ for data in transit. AES-256 at rest for sensitive credentials. Database backups are encrypted at rest.
Authentication
Email + password with rate-limiting. Optional 2FA via authenticator app or SMS. SSO and SAML available on Enterprise.
Authorization
Pundit-based policy enforcement on every controller. Configurable roles per account (Owner, Admin, Member, custom roles on Enterprise).
Audit log
Account-scoped audit trail of authentication, role changes, integration connections, value approvals, and admin actions. Available on paid plans.
AI providers
Anthropic Claude powers the in-app assistant. Your data is never used to train their models. See AI transparency below.
Hosting
Hosted on AWS in the United States. Application and background workers run in isolated containers behind a managed load balancer.
AI specifically
How we treat your data when AI is involved
Sub-processors
Who else touches your data
| Sub-processor | Purpose | Data location |
|---|---|---|
| AWS | Application hosting, database, file storage | United States |
| Stripe | Payments and subscription billing | United States / EU |
| Sentry | Application error monitoring | United States |
| Anthropic | AI assistant model provider (optional) | United States |
Compliance roadmap and questions
Roiva is pre-launch and actively scoping SOC 2 Type I (target: late 2026). If your team needs a security questionnaire, vendor risk review, or our latest sub-processor list — write to us and we'll respond within one business day.
security@roiva.ai