How It Works Outputs Pricing Security About Us
SECURITY AND TRUST

Built for accountants who cannot afford errors.

Every number Rocovit produces is traceable to its source. Every action is logged. Every file is protected.

AES-256 Encryption Full Audit Trail Data Isolation 7-Year Retention
HOW WE PROTECT YOUR DATA

Security built into every layer.

Data Encryption

All data transmitted to and from Rocovit is encrypted using AES-256 encryption - the same standard used by global financial institutions. Data at rest is encrypted before it is written to disk. No unencrypted data ever leaves our infrastructure.

AES-256-GCM - TLS 1.3 in transit - Encrypted at rest

Complete Data Isolation

Every accounting firm on Rocovit operates in a completely isolated environment. Your client data is never commingled with another firm's data. Database-level isolation means one firm cannot access, query, or affect another firm's records under any circumstance.

Tenant-level database isolation - No shared data stores

Full Audit Trail

Every allocation, journal adjustment, disclosure change, and export is logged with a timestamp, user identity, and before-and-after record. This is not just a security feature - it is your professional protection. If a financial statement is ever challenged, Rocovit gives you the complete documentation trail to defend every number.

Immutable logs - Timestamped - User-attributed - Exportable

Seven-Year Retention

Financial records are retained for seven years in line with regulatory requirements across our operating markets. You can access any prior year engagement at any time. When you need to delete data, submit a deletion request and it will be processed within 30 days.

7-year default retention - 30-day deletion processing - WORM-compliant storage

PROFESSIONAL PROTECTION

The audit trail that protects your licence.

When you sign off on a client's financial statements, your professional licence is on the line. Rocovit's immutable audit trail gives you the documentation to defend every number - the source transaction, the allocation decision, the schedule it mapped to, and the accountant who reviewed it. Every step. Every time.

Every transaction traced to its source bank record
Every allocation decision logged with confidence score and reviewer
Every output tied to the schedule data that generated it

"What used to take our team the better part of two weeks now takes a single morning. More importantly, we can now show exactly how every number was derived - something we could never do before."

AUDIT FIRM - LAGOS, NIGERIA

REGULATORY COMPLIANCE

Compliant across your markets.

Rocovit is built to meet data protection requirements across every market we serve.

NDPR

NIGERIA

Rocovit complies with the NDPR administered by the Nigeria Data Protection Commission. All personal data of Nigerian data subjects is processed lawfully, stored securely, and never transferred outside approved jurisdictions without adequate safeguards.

Lawful Processing Secure Storage Data Subject Rights

POPIA

SOUTH AFRICA

Rocovit meets POPIA requirements for any South African data subjects whose information is processed through the platform. We maintain the eight conditions for lawful processing and have appointed an Information Officer as required.

8 Lawful Conditions Information Officer Processing Limitation

GDPR

EUROPEAN UNION

Rocovit complies with GDPR requirements for any EU-based data subjects. We maintain a lawful basis for all processing, honour data subject rights including access and deletion, and implement privacy by design across the platform.

Lawful Basis Data Subject Rights Privacy by Design

SOC 2 Type II

GLOBAL STANDARD

Rocovit is currently undergoing SOC 2 Type II certification - the gold standard for SaaS data security trusted by enterprise accounting firms worldwide. Certification is expected in Q3 2026. Current security controls meet SOC 2 requirements in practice.

Security Availability Confidentiality In Progress
DATA PRACTICES

How your data is handled.

What we collect

Rocovit collects the financial data you upload or connect - bank statements, ledger exports, and prior year statements. We also collect account information for login and billing. We do not collect data beyond what is necessary to deliver the service.

What we never do

We never sell your data or your clients' data to any third party. We never use your client financial data to train AI models. We never share engagement data between firms. Your data is yours.

Your rights

You can request a full export of your data at any time. You can request deletion of your data and it will be processed within 30 days. You can request details of what data we hold about you. Contact privacy@rocovit.com for any data request.

COMMON QUESTIONS

Security questions answered.

Where is my data stored? +
Rocovit data is stored on enterprise-grade cloud infrastructure with servers located in compliant jurisdictions. All storage meets the data residency requirements of our operating markets including Nigeria, South Africa, and the EU.
Who can access my client data? +
Only authorised users within your firm can access your firm's data. Rocovit staff can access data only for the purpose of providing technical support and only with your explicit permission. All staff access is logged.
What happens to my data if I cancel? +
Your data remains available for 90 days after cancellation so you can export everything you need. After 90 days data is permanently deleted from our systems. You can request immediate deletion at any time.
Is my data backed up? +
Yes. All data is backed up continuously with point-in-time recovery available for the previous 30 days. Backups are encrypted and stored in geographically separate locations.
Can Rocovit use my data to train AI models? +
No. Your client financial data is never used to train any AI or machine learning model. It is used only to deliver the Rocovit service to your firm.
How does Rocovit handle a data breach? +
In the event of a confirmed breach affecting your data, we will notify you within 72 hours as required by GDPR and equivalent regulations. We maintain an incident response plan that is tested regularly.
Is Rocovit suitable for audit firms with professional secrecy obligations? +
Yes. Rocovit's data isolation, audit trail, and encryption architecture is designed to meet the confidentiality obligations of professional accounting and audit practices. The platform has been used by audit firms since launch.
How do I request my data or raise a privacy concern? +
Email privacy@rocovit.com. All requests are acknowledged within 48 hours and processed within 30 days as required by applicable data protection law.

First engagement free. No credit card. No commitment.

See what Rocovit does in under 3 hours.