Secure authentication
Passwords are strongly hashed and sessions use secure, HTTP-only cookies with controlled expiry.
Rostriva uses layered technical and organisational controls to protect customer workspaces and limit access to the people and sites a user is authorised to manage.
Start your workspacePasswords are strongly hashed and sessions use secure, HTTP-only cookies with controlled expiry.
Workspace roles and site scopes restrict sensitive actions and operational visibility.
Important access, configuration, workforce and rota actions create a traceable audit record.
Production services use encrypted connections, security headers and a managed PostgreSQL database in the Frankfurt region.
Stripe handles payment details; Rostriva does not receive or store complete card numbers or security codes.
The paid production database provides point-in-time recovery, supported by documented recovery procedures.