Security
Last updated: 3 July 2026
Encryption
All traffic is encrypted in transit with TLS. Backups are encrypted and stored off-site. Our infrastructure is hosted in the EEA (Germany).
Tenant isolation
Every organisation's data is isolated at the database layer with row-level security — isolation is enforced by the database itself on every query, not just by application code.
Accounts
Passwords are stored with strong one-way hashing, never in plain text. Login, signup and password-reset endpoints are rate-limited. Sessions are server-side and revocable.
Payments
Card details go directly to Stripe, a certified PCI-DSS Level 1 provider. Rotaleave never sees or stores card numbers.
Backups
Databases are backed up on a fixed schedule and — unusually — restores are tested automatically, so backups are known to work before they're needed.
Reporting a vulnerability
Found something? Email hello@rotaleave.co.uk with details. We take reports seriously, respond quickly, and won't pursue good-faith research.