Security
Last updated 28 September 2026
Small businesses trust us with their customers' phone numbers and notes. These are the measures we take to protect them.
Isolation between businesses
Every workspace's data is separated at the database level using row-level security, in addition to checks in the application. Automated tests verify that one workspace cannot read another's data.
Accounts and passwords
- Passwords are hashed with Argon2id; we never store or log them in readable form.
- Sessions and API keys are random tokens stored only as hashes. Refresh tokens rotate, and reuse of an old token signs the session out.
- Repeated failed sign-ins are rate-limited.
- Roles control who can see and change customers in team workspaces.
Data in transit and at rest
- All traffic uses HTTPS.
- Connector credentials are encrypted with AES-256-GCM.
- Backups are encrypted and restore tests are run regularly.
- On Android and iOS, sign-in tokens are kept in the device's secure storage (Keystore / Keychain).
Payments
Payments are processed by Razorpay. Every payment confirmation is verified with a cryptographic signature on our server; a payment reference typed by a customer is never treated as confirmed until it is reconciled.
Integrations
Webhooks are signed and time-stamped. The REST connector refuses to call private network addresses. RootCue never changes the structure of connected systems.
Reporting a vulnerability
If you believe you've found a security issue, email support@rootpro.in with “Security” in the subject. Please give us reasonable time to fix it before sharing it publicly. We don't take legal action against good-faith research.