Skip to content

Legal

Security & Data Handling

Last updated August 16, 2026

This page describes how we protect roai.us and the data that runs through it.

Infrastructure

The site runs on Vercel and Neon (Postgres). Traffic to the site is encrypted in transit with TLS 1.3. Data at rest in our database and in private file storage is encrypted by our infrastructure providers.

Access control

We follow the principle of least privilege: team members and automated systems get access only to the systems and data they need for their specific role. Sign-in to our own systems requires multi-factor authentication where the provider supports it.

Client data during engagements

For advisory engagements, what client data we accept and how we handle it is agreed with each client before any data is shared, and is scoped narrowly to what the engagement needs. We don't put client-identifying data into a general-purpose AI model without that client's explicit agreement.

Subprocessors

The same processors named in our Privacy Policy: Vercel, Neon, Google, Stripe, Resend, Cloudflare, and Upstash.

Incident response

If we discover a security incident affecting your data, we'll investigate promptly, take steps to contain it, and notify affected individuals and any authority we're legally required to notify, without undue delay and in line with applicable law.

Reporting a vulnerability

If you find a security issue on roai.us, please tell us before disclosing it publicly: security@roai.us, or see /.well-known/security.txt. We'll acknowledge your report and keep you updated as we work on a fix.

Certifications

We hold no third-party security certifications (such as SOC 2) at this time. We're stating that plainly rather than implying otherwise, because an unverified claim is worse than no claim at all. If that changes, we'll update this page.