SOC2C

Rosterfy security & compliance

An overview of Rosterfy's security posture — compliance, penetration testing, subprocessors, and data handling — verified on SOC2C (Listed).

SOC 2 statusSOC 2 Type II · Listed
FrameworksISO 27001, SOC 2 Type II
Penetration testNot listed
Subprocessors22 listed
HostingAWS, GCP
Trust centerView

Security questions about Rosterfy

Is Rosterfy secure?
Security isn't a single yes/no, but Rosterfy is SOC 2 Type II compliant and holds ISO 27001, SOC 2 Type II. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Rosterfy have a bug bounty or vulnerability disclosure program?
Rosterfy hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@rosterfy.com or via a /security page (Rosterfy lists a security contact).
Who are Rosterfy's subprocessors?
Rosterfy lists 22 subprocessors on its trust center, including Amazon Web Services, Intercom, Lacework, Hubspot, Twilio. Buyers use this for fourth-party risk review.
Where does Rosterfy host or store data?
Rosterfy hosts on AWS, GCP, and handles Customer personally identifiable information, Employee personally identifiable information, Credit card information, Personal health information. Data residency details are on its trust center.
Where is Rosterfy's trust center or security page?
Rosterfy's trust center is at https://trust.rosterfy.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.

See Rosterfy's full SOC 2 profile →