Rockbase

Security

One region. One subprocessor.

Rockbase holds how a company runs, which is not the kind of data you hand over on the strength of a badge. So: where it lives, who can reach it, and the bar a vendor clears before it joins the list. Nothing here is something you have to take on trust.

1
sub-processor

Google. That is the entire list.

1
region

europe-west2, London. Nothing moves for convenience.

0
trackers on this site

No analytics, no pixels, no cookies.

0
audit records we can delete

Append-only. That includes us.

Where it is

Your data sits inside one boundary.

Most products in this category are a thin layer over a dozen vendors. Rockbase runs the parts that hold your data itself, in one project, in one region — including the two things almost everyone rents.

OUR GOOGLE CLOUD PROJECT · EUROPE-WEST2 (LONDON)PostgresYour records, row-level isolatedAPI (Cloud Run)Behind two gatesProduct appapp.rockbase.appIdentity providerSelf-hosted, not a vendorWorkflow engineSelf-hosted, not a vendorVertex AIClaude, pinned to the EUEncrypted in transit and at rest. Least-privilege service identities: the runningapplication cannot alter its own database structure.Accounts are isolated from one another by the database, not by the interface.Outbound account email — the only exit
Identity and orchestration are the two things most products rent from a vendor. We run both ourselves, in the same region as your data — which is why neither appears as a sub-processor below.

How access is decided

Six controls that do the actual work.

Isolation is enforced at the database.

Not in the interface, and not in a middleware someone can forget to apply. A request that should see nothing sees nothing, whatever route it arrives by — and every change to the system re-runs the isolation tests, which fail the build rather than filing a warning.

Two gates front the data.

The platform refuses an unauthenticated caller before our code runs at all; then our own verifier checks the token and resolves who you are. They fail differently on purpose, so we can tell which one refused you.

Authentication bought, authorization built.

The identity provider owns who you are. Rockbase owns what you can see and do, in rings — and sensitive people data sits behind its own ring rather than being visible to anyone who can see the person.

Least privilege, including for us.

The running application holds a database identity that cannot alter its own schema; structural changes run as a separate, deliberate step. Our own access is limited to running and supporting the service, and it is audited like everyone else's.

One route to the model.

Every AI call goes through a single internal gateway — metered, capped, and pinned to the EU. There is no second path, which is what makes that claim checkable rather than a promise.

Inviting is granting access.

So only an account owner can invite. Binding a login to a person's record means being able to act as them, and treating that as an HR task rather than a security one is how privilege quietly escalates.

The bar

What a vendor has to clear before it touches anything.

Every third party that touches customer data is a sub-processor, and every one of them is a decision we have to defend. So the bar is written down, and it is stricter for data that matters more.

TIER A

Identity, your records, anything sensitive

Strict, no exceptions: data stays in the European region — or the component runs self-hosted in our own — and the vendor holds SOC 2 Type II and/or ISO 27001. This covers sign-in, your records, workflow state, anything a model sees, and data pulled from systems you connect.

Where a vendor could not meet it, we built or self-hosted instead. That is the honest reason this list is short.

TIER B

Operational telemetry and payments

Relaxed, and stated as such: SOC 2 Type II plus a data processing agreement with a lawful transfer mechanism. Payment processors are separate controllers under card-scheme rules, where global processing is the norm and pretending otherwise would be a fiction.

We would rather tell you which tier something sits in than describe everything as enterprise-grade.

Sub-processors

The whole list, which is one company.

We would rather show you a short true list than a long reassuring one. When something is added, it appears here before it starts processing — not after.

Sub-processorWhat forWhereTierBasis
Google CloudThe platform Rockbase runs on — database, storage, compute, secretseurope-west2 (London), our own projectsAProcessor under our Google Cloud terms
Google Cloud (Vertex AI)Claude model inferenceEU-pinnedAProcessor under our Vertex terms
Google WorkspaceSending invitation and account emailEUBProcessor under our Workspace terms

Not on this list, deliberately: the identity provider and the workflow engine. Both are self-hosted in our own region, so no third party holds your credentials or your workflow state. Vendors that failed the bar are recorded internally with the reason — a rejection is evidence too, and we would rather keep that record honest than publish it as marketing.

Commitments

What we will not do.

  • Sell or share your data. There is no advertising network anywhere in this product.
  • Train models on your data, or let anyone else do so on our behalf.
  • Put your data in a US region, or in a database shared with another customer.
  • Run AI on credit — usage is prepaid and capped, so there is no bill you did not see coming.
  • Publish an uptime figure we have not earned the operating history to stand behind.
  • Threaten anyone who reports a vulnerability to us.

Found something?

Tell us at security@rockbase.app and we will work with you on it. No system is perfect and we do not claim ours is — what we can promise is that you will get a real person who wants to fix it, and that we will never threaten you for reporting it.

For what we hold and why, see the privacy notice. For how good records become audit evidence, see ISO 9001.

Build on solid ground.

We're taking on a small number of founding clients. If your strategy and your work have drifted apart, let's fix the foundation.

Apply for early access