Security & Trust

Built for the controls enterprise teams require

Roiva handles initiative metadata, integration credentials, and aggregated metric data — and we treat all of it with the controls a finance team would expect.

What we do, end to end

Encryption

TLS 1.2+ for data in transit. AES-256 at rest for sensitive credentials. Database backups are encrypted at rest.

Authentication

Email + password with rate-limiting. Optional 2FA via authenticator app or SMS. SSO and SAML available on Enterprise.

Authorization

Pundit-based policy enforcement on every controller. Configurable roles per account (Owner, Admin, Member, custom roles on Enterprise).

Audit log

Account-scoped audit trail of authentication, role changes, integration connections, value approvals, and admin actions. Available on paid plans.

AI providers

Anthropic Claude powers the in-app assistant. Your data is never used to train their models. See AI transparency below.

Hosting

Hosted on AWS in the United States. Application and background workers run in isolated containers behind a managed load balancer.

How we treat your data when AI is involved

Your data is never used to train AI models. Roiva uses Anthropic Claude to power the in-app assistant. Anthropic is configured with data-processing terms that prohibit training on your inputs. Only the minimum context required for an answer (initiative titles, metric summaries, ROI figures) is sent. Read the AI transparency statement for the full breakdown.

Who else touches your data

Sub-processor Purpose Data location
AWS Application hosting, database, file storage United States
Stripe Payments and subscription billing United States / EU
Sentry Application error monitoring United States
Anthropic AI assistant model provider (optional) United States

Compliance roadmap and questions

Roiva is pre-launch and actively scoping SOC 2 Type I (target: late 2026). If your team needs a security questionnaire, vendor risk review, or our latest sub-processor list — write to us and we'll respond within one business day.

security@roiva.ai