SOC2C

Is this your company? Buyers are checking Rosterfy here. Claim rosterfy.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Rosterfy logo

Rosterfy

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Rosterfy is SOC 2 Type II compliant. Rosterfy also holds ISO 27001.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Our end-to-end Volunteer Management Software redefines how organizations achieve cost efficiencies, scalability and ensure compliance with volunteer programs.

Compliance & infrastructure

Hosting
AWSGCP
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health information

Documents

3

Subprocessors

22
  • A
    Amazon Web Services · Cloud provider
    USA, France, UK, Australia, Germany, Canada
  • I
    Intercom · Customer support
    USA
  • L
    Lacework · Threat detection, workload monitoring
    USA, France, Australia, London
  • H
    Hubspot · Knowledge Base, Support Desk
    USA
  • T
    Twilio · SMS Messaging
    USA
  • P
    Pusher · Engineering
    Australia, United Kingdom, USA, France & Germany
  • P
    Planhat · Customer account management
    USA
  • F
    Fireflies · Customer support
    USA
  • D
    Dovetail · Product and design
    USA
  • L
    Loom · Account Management
    Loom
  • P
    Pendo · Customer Management
    USA
  • J
    Jiminny · Account Management
    USA, Ireland, UK
Show all 22 subprocessors
  • Q
    Qwilr · Quote management service
    Australia
  • X
    Xero · Finance and payments
    USA, Australia, UK, Ireland
  • C
    Chaser · Invoicing tool
    UK
  • C
    CrossBeam · used for partner relationship management. Can identify companies where we can wo
    USA
  • J
    Juro · Contract Management
    UK, EEA
  • S
    Stream · Engineering
    Germany, Europe
  • A
    Absorb Software Inc · Internal Learning Management System
    Ireland
  • G
    Google LLC / Google Cloud Looker · Embedded analytics and dash boarding for Rosterfy Analytics
    Frankfurt, Germany
  • G
    Google LLC / Google Cloud BigQuery · Rosterfy Analytics data warehouse Location:
    Multi-region: EU, AU, USA
  • A
    Anthropic · Component to Rosterfy's AI Agent for Volunteer Managers

Compliance leadership

The person who leads Rosterfy's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Rosterfy's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Rosterfy SOC 2 compliant?
Rosterfy is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Rosterfy ISO 27001 certified?
According to Rosterfy's public trust center, Rosterfy is ISO 27001 certified. On SOC2C this listing is Listed.
Is Rosterfy SOC 2 Type I or Type II?
Rosterfy is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Rosterfy's SOC 2 for a vendor risk assessment?
Yes. Rosterfy's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Rosterfy penetration tested?
Rosterfy hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.

Answers published by Rosterfy

Reproduced from Rosterfy's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Do you support Single Sign-On (SSO)?
Yes. Rosterfy supports single sign-on for customers through their Identity Providers. Rosterfy supports both SAML and OpenID SSO protocols to ensure our platform is compatible with your Identity Provider. We also support user provisioning, and role based access from your Identity Provider. SSO can be run either as an optional authentication method, or enforced for different user types. Most commonly our customers will use SSO for their enterprise users, and allow their workforce to use social logins, or usernames and passwords.
Where are your servers located?
Rosterfy has shared tenancy application environments in the USA (Ohio), Canada (Montreal), UK (London), France (Paris) and Australia (Sydney). We also can support single tenancy environments in any AWS region at an additional license cost.
Do you encrypt data at rest?
Rosterfy uses the industry standard AES-256 encryption algorithm to encrypt your data at rest. Backups are encrypted using Rosterfy customer keys to ensure it is not accessible to any other users of AWS infrastructure. Backups are immutable and stored at separate physical sites for maximum availability.
Do you have an API?
Rosterfy has an API that is available to all of our customers. API documentation can be found on our website. Our API uses Oauth tokens specific to a user of the application. Our API allows any of our customers to integrate the platform with their own tools or other systems. We also offer a webhook module so that you can setup callbacks to your own HTTPS platform when events occur in Rosterfy. Other interfaces to the Rosterfy application include - AWS SNS or Azure Service Bus Integrations for Rosterfy to stream messages to your service or subscription - SFTP of files to your own application server - 30+ integrations with existing vendors to integrate the Rosterfy application with other industry suppliers
Do you run Vulnerability and Penetration tests?
Yes, Rosterfy has a robust security program supported by vulnerability and penetration testing. We have a number of platforms constantly monitoring Rosterfy infrastructure and services for vulnerabilities. We also have penetration tests conducted by CREST certified penetration testers. On request we can provide the latest VAPT testing reports.

Business & Industrial peers that completed SOC 2