Security

Trust is earned
in the details.

Candidate data treated as what it is: a private life, not a record. This page is our living commitment — what we have shipped, what we are building, and who to ask for the current posture.

Security posture
Encryption in transit
TLS on every request
Encryption at rest
Handled by our cloud provider
Rook ID as the directory
One identity across every Rook product
Audit log
Every action, timestamped
Least privilege tokens
Scoped per action, revocable
Workspace isolation
Permissions never leak across spaces
TLS
Encryption on every request
Audit
Every action, timestamped
Rook ID
One directory, every product
Contact
For current compliance posture

What we commit to

Private by design.
Controls that earn the trust.

Your data is yours

Rook does not train on your workspace. Candidate data is read, scored, and handed back. Nothing sold, nothing repurposed.

Encryption

Every request travels over TLS. Data at rest is encrypted through our cloud provider. Keys are rotated on the provider schedule.

Rook ID as the directory

One identity signs into every Rook product. SSO via SAML and OIDC is on the roadmap — talk to us if you need it today.

Audit log

Every action written with actor, timestamp, and resource. Exportable on request.

Least privilege tokens

Integrations ask for the narrowest scope. Tokens are revocable per workspace and rotate on the provider schedule.

Workspace isolation

Permissions never leak across workspaces. Even an admin in one is a guest in another until invited.

FAQ

Questions, answered.

No. Your data is used to answer your questions and nothing else. Training sets are built from public, opt in, or synthetic data only.

Private by design.
Honest about where we are.

Ask for our current security posture before a procurement review. We would rather tell you where we are than promise a badge we do not have.