Skip to content
RootCueby RootPro Technologies

Security

Last updated 28 September 2026

Small businesses trust us with their customers' phone numbers and notes. These are the measures we take to protect them.

Isolation between businesses

Every workspace's data is separated at the database level using row-level security, in addition to checks in the application. Automated tests verify that one workspace cannot read another's data.

Accounts and passwords

  • Passwords are hashed with Argon2id; we never store or log them in readable form.
  • Sessions and API keys are random tokens stored only as hashes. Refresh tokens rotate, and reuse of an old token signs the session out.
  • Repeated failed sign-ins are rate-limited.
  • Roles control who can see and change customers in team workspaces.

Data in transit and at rest

  • All traffic uses HTTPS.
  • Connector credentials are encrypted with AES-256-GCM.
  • Backups are encrypted and restore tests are run regularly.
  • On Android and iOS, sign-in tokens are kept in the device's secure storage (Keystore / Keychain).

Payments

Payments are processed by Razorpay. Every payment confirmation is verified with a cryptographic signature on our server; a payment reference typed by a customer is never treated as confirmed until it is reconciled.

Integrations

Webhooks are signed and time-stamped. The REST connector refuses to call private network addresses. RootCue never changes the structure of connected systems.

Reporting a vulnerability

If you believe you've found a security issue, email support@rootpro.in with “Security” in the subject. Please give us reasonable time to fix it before sharing it publicly. We don't take legal action against good-faith research.