Security
One region. One sub‑processor.
Rockbase holds how a company runs, which is not the kind of data you hand over on the strength of a badge. So: where it lives, who can reach it, and the bar a vendor clears before it joins the list. Nothing here is something you have to take on trust.
- 1
- sub-processor
- 1
- region
- 0
- trackers on this site
- 0
- audit records we can delete
Google. That is the entire list.
europe-west2, London. Nothing moves for convenience.
No analytics, no pixels, no cookies.
Append-only. That includes us.
Where it is
Your data sits inside one boundary.
Most products in this category are a thin layer over a dozen vendors. Rockbase runs the parts that hold your data itself, in one project, in one region — including the two things almost everyone rents.
How access is decided
Six controls that do the actual work.
Isolation is enforced at the database.
Not in the interface, and not in a middleware someone can forget to apply. A request that should see nothing sees nothing, whatever route it arrives by — and every change to the system re-runs the isolation tests, which fail the build rather than filing a warning.
Two gates front the data.
The platform refuses an unauthenticated caller before our code runs at all; then our own verifier checks the token and resolves who you are. They fail differently on purpose, so we can tell which one refused you.
Authentication bought, authorization built.
The identity provider owns who you are. Rockbase owns what you can see and do, in rings — and sensitive people data sits behind its own ring rather than being visible to anyone who can see the person.
Least privilege, including for us.
The running application holds a database identity that cannot alter its own schema; structural changes run as a separate, deliberate step. Our own access is limited to running and supporting the service, and it is audited like everyone else's.
One route to the model.
Every AI call goes through a single internal gateway — metered, capped, and pinned to the EU. There is no second path, which is what makes that claim checkable rather than a promise.
Inviting is granting access.
So only an account owner can invite. Binding a login to a person's record means being able to act as them, and treating that as an HR task rather than a security one is how privilege quietly escalates.
The bar
What a vendor has to clear before it touches anything.
Every third party that touches customer data is a sub-processor, and every one of them is a decision we have to defend. So the bar is written down, and it is stricter for data that matters more.
Identity, your records, anything sensitive
Strict, no exceptions: data stays in the European region — or the component runs self-hosted in our own — and the vendor holds SOC 2 Type II and/or ISO 27001. This covers sign-in, your records, workflow state, anything a model sees, and data pulled from systems you connect.
Where a vendor could not meet it, we built or self-hosted instead. That is the honest reason this list is short.
Operational telemetry and payments
Relaxed, and stated as such: SOC 2 Type II plus a data processing agreement with a lawful transfer mechanism. Payment processors are separate controllers under card-scheme rules, where global processing is the norm and pretending otherwise would be a fiction.
We would rather tell you which tier something sits in than describe everything as enterprise-grade.
Sub-processors
The whole list, which is one company.
We would rather show you a short true list than a long reassuring one. When something is added, it appears here before it starts processing — not after.
| Sub-processor | What for | Where | Tier | Basis |
|---|---|---|---|---|
| Google Cloud | The platform Rockbase runs on — database, storage, compute, secrets | europe-west2 (London), our own projects | A | Processor under our Google Cloud terms |
| Google Cloud (Vertex AI) | Claude model inference | EU-pinned | A | Processor under our Vertex terms |
| Google Workspace | Sending invitation and account email | EU | B | Processor under our Workspace terms |
Not on this list, deliberately: the identity provider and the workflow engine. Both are self-hosted in our own region, so no third party holds your credentials or your workflow state. Vendors that failed the bar are recorded internally with the reason — a rejection is evidence too, and we would rather keep that record honest than publish it as marketing.
Commitments
What we will not do.
- Sell or share your data. There is no advertising network anywhere in this product.
- Train models on your data, or let anyone else do so on our behalf.
- Put your data in a US region, or in a database shared with another customer.
- Run AI on credit — usage is prepaid and capped, so there is no bill you did not see coming.
- Publish an uptime figure we have not earned the operating history to stand behind.
- Threaten anyone who reports a vulnerability to us.
Found something?
Tell us at security@rockbase.app and we will work with you on it. No system is perfect and we do not claim ours is — what we can promise is that you will get a real person who wants to fix it, and that we will never threaten you for reporting it.
For what we hold and why, see the privacy notice. For how good records become audit evidence, see ISO 9001.
Build on solid ground.
We're taking on a small number of founding clients. If your strategy and your work have drifted apart, let's fix the foundation.
Apply for early access