Security
Last updated 3 August 2026
# Security at Rovaxa
**Last updated: 3 August 2026**
Rovaxa builds execution systems used to support industrial operations, employee operations and customer operations. We recognise that security, confidentiality, availability and integrity are essential to the trust customers place in these systems.
This page describes Rovaxa’s general security approach. Controls may differ by product, deployment model, subscription, customer configuration and contractual scope. This page is informational and does not create a warranty, certification, service level or contractual commitment. Applicable commitments are stated in the relevant customer agreement.
1. Security principles
Our security approach is guided by the following principles:
- **Secure by design:** security is considered during architecture, development and change decisions.
- **Least privilege:** access should be limited to what is needed for a legitimate role or task.
- **Defence in depth:** multiple preventive, detective and responsive safeguards are used where appropriate.
- **Customer control:** customers should be able to manage their users, roles and operational configuration.
- **Traceability:** important administrative, authentication and system events should be logged where supported.
- **Continuous improvement:** risks, dependencies and safeguards are reviewed as products and threats evolve.
2. Application and development security
Depending on the product and release process, our practices may include:
- defined development and change-management processes;
- separation of development, testing and production activities where appropriate;
- peer review and automated checks for code changes;
- dependency and vulnerability review;
- secure configuration and secrets-management practices;
- testing before production release;
- controlled deployment and rollback processes; and
- remediation prioritised according to severity, exploitability and customer impact.
3. Identity and access management
Rovaxa products are designed to support controlled user access. Available controls may include:
- unique user accounts;
- role-based access controls;
- administrator-managed permissions;
- password and authentication safeguards;
- session controls;
- account deactivation; and
- logging of significant access and administrative events.
Customers are responsible for assigning appropriate administrators, maintaining accurate user access, protecting credentials, removing access when it is no longer required, and configuring available controls for their environment.
4. Data protection
We use technical and organisational measures appropriate to the service and risk. These may include:
- encryption of supported data in transit;
- encryption at rest where provided by the hosting or storage service;
- access restrictions for production systems and customer information;
- backup and recovery measures appropriate to the service design;
- tenant or logical access separation in multi-customer services;
- secure disposal or deletion processes; and
- monitoring and logging designed to support investigation and reliability.
Specific data location, retention, backup, recovery and deletion commitments are governed by the applicable customer agreement and service configuration.
5. Infrastructure and service providers
Rovaxa may use established hosting, cloud, database, communications and security providers to operate its services. We evaluate providers according to the nature of the service and the information involved, limit access to authorised purposes, and use contractual safeguards where appropriate.
Cloud-provider security does not remove the shared responsibility of Rovaxa and its customers. Customers remain responsible for their users, devices, networks, configurations, integrations and data-entry decisions unless a written agreement states otherwise.
6. Availability, backup and recovery
We design services with reliability and recoverability appropriate to their intended use. Measures may include service monitoring, managed infrastructure, health checks, backups, restoration procedures and deployment rollback capability.
No online service can guarantee uninterrupted operation. Product-specific availability, recovery objectives, maintenance arrangements and support commitments apply only when included in the relevant customer agreement.
7. Vulnerability management
We review security information relevant to our software and service providers and prioritise remediation based on risk. We may use automated scanning, dependency alerts, testing and manual review as appropriate.
Customers and security researchers should report suspected vulnerabilities responsibly through the process below. Do not publicly disclose a suspected vulnerability before Rovaxa has had reasonable time to investigate and address it.
8. Security incident response
Rovaxa maintains an approach for assessing and responding to suspected security incidents. Depending on the circumstances, response activities may include validation, containment, investigation, remediation, recovery and lessons learned.
Where an incident affects customer information, we will communicate with affected customers in accordance with applicable law and contractual obligations.
9. Responsible vulnerability disclosure
If you believe you have found a security vulnerability in a Rovaxa website or service:
1. Use the contact form at **rovaxa.in/contact**.
2. State clearly that the message is a **Security Vulnerability Report**.
3. Provide the affected URL or product, a clear description, reproduction steps and the potential impact.
4. Include supporting screenshots or logs only after removing personal information, credentials and customer data.
5. Allow reasonable time for investigation and remediation before any public disclosure.
Please do not:
- access, alter, retain or disclose data that does not belong to you;
- degrade, disrupt or deny service;
- use social engineering, phishing, physical attacks or credential attacks;
- run destructive tests or automated high-volume scanning;
- install malware or create persistence;
- demand payment as a condition of withholding disclosure; or
- violate any law or third-party right.
Rovaxa does not currently operate a public bug-bounty programme. Submission of a report does not create an entitlement to payment. We will nevertheless value good-faith reports and may acknowledge a reporter when appropriate and mutually agreed.
10. Customer security responsibilities
Security is shared. Customers should:
- designate trained and accountable administrators;
- apply least privilege when assigning access;
- use strong, unique credentials and available authentication controls;
- promptly disable access for departing or transferred personnel;
- maintain secure user devices, browsers and networks;
- review roles, integrations and logs regularly;
- validate data before uploading it;
- avoid storing information not needed for the agreed purpose;
- report suspected compromise promptly; and
- maintain appropriate business-continuity procedures for critical operations.
Rovaxa platforms should not be treated as substitutes for safety-instrumented systems, emergency controls or other systems whose failure could directly cause death, personal injury or severe physical or environmental damage, unless Rovaxa has expressly agreed in writing that a specific service is designed and contracted for that use.
11. Security enquiries
For security questionnaires, architecture discussions or responsible vulnerability reports, visit **rovaxa.in/contact** and identify the enquiry as a security matter.