Legal
Security & Data Handling
Last updated August 16, 2026
This page describes how we protect roai.us and the data that runs through it.
Infrastructure
The site runs on Vercel and Neon (Postgres). Traffic to the site is encrypted in transit with TLS 1.3. Data at rest in our database and in private file storage is encrypted by our infrastructure providers.
Access control
We follow the principle of least privilege: team members and automated systems get access only to the systems and data they need for their specific role. Sign-in to our own systems requires multi-factor authentication where the provider supports it.
Client data during engagements
For advisory engagements, what client data we accept and how we handle it is agreed with each client before any data is shared, and is scoped narrowly to what the engagement needs. We don't put client-identifying data into a general-purpose AI model without that client's explicit agreement.
Subprocessors
The same processors named in our Privacy Policy: Vercel, Neon, Google, Stripe, Resend, Cloudflare, and Upstash.
Incident response
If we discover a security incident affecting your data, we'll investigate promptly, take steps to contain it, and notify affected individuals and any authority we're legally required to notify, without undue delay and in line with applicable law.
Reporting a vulnerability
If you find a security issue on roai.us, please tell us before disclosing it publicly: security@roai.us, or see /.well-known/security.txt. We'll acknowledge your report and keep you updated as we work on a fix.
Certifications
We hold no third-party security certifications (such as SOC 2) at this time. We're stating that plainly rather than implying otherwise, because an unverified claim is worse than no claim at all. If that changes, we'll update this page.