This page describes Rowsh's security practices. It does not represent a certification, independent audit, penetration test result, or service level commitment.
1. Workspace and access controls
- Tenant aware database and request paths scope workspace operations to the authenticated customer environment.
- Role and module permission checks govern administrative and product access.
- Multi factor authentication is available, with enrolment, trusted device, and session management controls.
- Security relevant events are recorded in workspace audit logs where the relevant feature supports them.
2. Authentication and data protection
Rowsh uses password hashing, short lived access tokens, rotating refresh sessions, secure cookie attributes in production, origin checks for cookie authenticated state changes, and transport encryption at the deployed edge. Production uploads are encrypted with application layer AES 256 GCM before they are written to object storage. Selected secrets and message content paths also use application level encryption.
3. Application safeguards
Rowsh applies tenant scoping, server side validation and authorisation, abuse controls on relevant public paths, signed webhook verification, and protected configuration paths for provider credentials. Security also depends on deployment configuration, timely maintenance, provider controls, and customer administration.
4. Customer responsibilities
Customers must configure roles and integrations carefully, require appropriate account safeguards, remove access promptly, protect exports and API credentials, review audit information, and report suspected incidents. Do not share passwords or place production secrets in workspace content.
5. Responsible disclosure
Send a vulnerability report to team@rowsh.com or use the Contact page with "Security report" selected. Include the affected URL or component, reproduction steps, impact, and safe supporting evidence. Do not include customer data you are not authorised to access.
6. Safe research rules
- Use accounts and data you own or have written permission to test.
- Do not access, alter, retain, or disclose another person's data.
- Do not use denial of service, destructive testing, social engineering, spam, or automated activity that degrades the Service.
- Stop and report if you encounter sensitive information or an unexpected impact.
- Allow a reasonable investigation and remediation period before public disclosure.
7. Response and recognition
Rowsh reviews good faith reports and communicates as reasonably practicable based on severity and available evidence. This page does not promise a fixed response or remediation time, monetary reward, public recognition, safe harbour, or authorisation to test third party systems. Any separate commitment must be confirmed in writing by Rowsh.
8. Incidents and updates
Rowsh handles confirmed incidents according to applicable law and customer contracts. Material changes to this page are dated and published through the Legal Center.