[ Last reviewed ]

The ROIkeep security record

The mechanisms that are shipped and the certifications and tests that are not held, stated at the level of mechanism rather than reassurance.

ROIkeep holds no security certification or attestation today. No penetration test and no external audit have been performed: no independent testing of any kind. Stored secrets and sensitive people records are encrypted at rest with AES-256-GCM.

In place of a certificate, this page states the record: mechanisms that are shipped, described precisely, with tenancy and hosting named per plan. The absences are stated as directly as the mechanisms.

[ Gaps ]

What is not held

Security certification or attestation

No security certification or attestation is held today. SOC 2 is planned. No audit has begun and no report exists.

Penetration test

No penetration test has been performed.

External security audit

No external audit has been performed.

ISO/IEC 27001

ISO 27001 is not held. ROIkeep is hosted in ISO 27001 certified data centres; that certification belongs to the hosting providers, not to ROIkeep.

[ Mechanisms ]

What is in place

Encryption at rest

Stored secrets and sensitive people records, meaning national ID, salary, bank account, and IBAN, are encrypted at rest with AES-256-GCM. That covers vault values (credentials, environment variables, secure notes) and the named fields of a people record. It applies on every plan.

See the credentials vault
Secret values in logs

Secret values are never written to any log. This holds for vault secret values across the product.

Access revocation

Removing a person is one action. It bans them from every connected app, ends their active sessions, and writes an audit entry. Removal is performed by an owner. The revocation webhook is signed with HMAC and carries a five minute timestamp window.

See single sign-on
Sessions and devices

Sessions and devices are revocable per person. Revocation is performed by an owner from the hub console; the shipped console offers no self-service revocation. Device sign-in enforcement applies to enrolled Windows and Linux computers.

One-time secret handoff

A single credential, environment value, or note can be sent to one person with an expiry, without granting vault access. It is destroyed the moment it is opened or revoked, and unreadable the moment it expires. The sender sees whether it was collected.

Import preview

A Bitwarden JSON import shows exactly what will be created before anything is written, and lands as one change or not at all. It runs on an unencrypted export; encrypted exports are refused, and unsupported types are reported with a reason. There is no undo once an import lands.

[ Data ]

Where the data lives, and what leaves with you

Tenancy
Essential customers run on shared tenancy. Private and Custom customers each get their own single-tenant instance: a separate project, a separate server, and a separate database per customer.
Hosting
Essential runs on Hetzner. Private and Custom run on AWS. Every plan is hosted in ISO 27001 certified data centres; those certifications are held by the hosting providers, not by ROIkeep.
Managed access
A Private or Custom customer receives no SSH access, no operating system access, no hosting account, and no direct database access. Both are fully managed instances, controlled through the product rather than through the infrastructure.
Source code
Product source code is never shared: on any plan, at any price, including custom development work built for that customer.
Data out
Any table view exports to CSV or PDF. A customer who leaves receives a full export of their data in CSV, PDF, and JSON.
When access ends
Access ends in one action when a person leaves.See access revocation

If your checklist has a row this page does not answer, send it to us.

Shorter operational questions are answered at the FAQ, which links back here for mechanism detail.