Security
Last updated: May 2026
Commitment
We protect personal data with technical and organizational controls aligned with applicable privacy law. See /privacy for details.
Technical controls
Mandatory HTTPS in production, secure password hashing, CSRF on mutating routes, admin RBAC, rate limiting on sensitive APIs, prior consent for analytics, and audit trails on critical actions.
Operations
Database backups per provider, weekly automated retention (consent logs, audit logs, inactive registrations), environment separation, and no production dumps in local development.
Incidents
Incidents are recorded internally, classified by severity, and handled per our response plan. Report concerns via the privacy contact email.
Contact
Security or privacy questions: use the channel in our privacy policy or privacy@rotalabs.co.
