Skip to content
RotaLabs

Security

Last updated: May 2026

Commitment

We protect personal data with technical and organizational controls aligned with applicable privacy law. See /privacy for details.

Technical controls

Mandatory HTTPS in production, secure password hashing, CSRF on mutating routes, admin RBAC, rate limiting on sensitive APIs, prior consent for analytics, and audit trails on critical actions.

Operations

Database backups per provider, weekly automated retention (consent logs, audit logs, inactive registrations), environment separation, and no production dumps in local development.

Incidents

Incidents are recorded internally, classified by severity, and handled per our response plan. Report concerns via the privacy contact email.

Contact

Security or privacy questions: use the channel in our privacy policy or privacy@rotalabs.co.