Security & Privacy at ROQA AI

At ROQA AI, security and privacy are foundational to how we build our products. This page summarizes how ROQA AI protects customer data, the certifications we hold, and the commitments we make to every customer.

Last updated: March 2026
Contact: security@roqaai.com

About ROQA AI

ROQA AI provides two products serving the UiPath ecosystem:

Our customers are RPA service providers, UiPath license distributors, and automation Centers of Excellence — organizations who build, sell, or operate UiPath automation at scale.

Our Security Commitments

Data minimization. We collect only the operational telemetry required to deliver MonA and AriA by default. Transaction-level data (bot execution logs and queue items) is processed only when a user of AriA explicitly requests analysis of it.

Encryption in transit and at rest. All data is encrypted in transit via TLS 1.2+ and at rest using AES-256.

Access on a need-to-know basis. Production access is limited to authorized engineering personnel, protected by multi-factor authentication and logged.

No training on customer data. Customer data is never used to train or fine-tune any AI model — ours or any third party's. Anthropic's API, which powers AriA, operates under a zero-retention policy for API traffic per Anthropic's commercial terms.

EU data residency. All customer data is processed and stored in the European Union. LLM inference performed by Anthropic's API is subject to international transfer safeguards described in the Subprocessors section below.

Customer control over AI access to sensitive data. Customers can restrict which users are authorized to invoke AriA's transaction-level analysis feature, or disable the feature entirely.

Infrastructure

LayerDetails
Cloud hostingMicrosoft Azure
Primary regionWest Europe
DatabasePostgreSQL (managed), Microsoft SQL Server
Application runtimeApp Service hosts serving the MonA and AriA APIs
Network isolationPrivate networking between services; no direct public database exposure
BackupsAutomated daily backups, encrypted, retained 35 days
Disaster recoveryRTO: 8 hours, RPO: 24 hours

Application Security

AI Processing & Anthropic (AriA only)

AriA uses Anthropic's Claude API to convert natural-language questions about your UiPath estate into operational answers. The following applies specifically to AriA.

Model routing

AriA uses multiple Claude models from Anthropic. Requests involving sensitive data analysis or multi-step reasoning are routed to Anthropic's more capable reasoning models, while lighter-weight tasks such as short conversational replies, formatting, and simple lookups are routed to faster, more efficient models. Routing is managed by AriA and is not user-selectable.

Data sent to Anthropic — baseline operational queries

For most AriA interactions, only the user's prompt and UiPath operational metadata (job names, statuses, timestamps, error messages) are sent to the model. No transaction-level content is sent in this mode.

Data sent to Anthropic — on-demand transaction-level analysis

When a user of AriA explicitly requests analysis of transaction-level detail, AriA retrieves the relevant UiPath bot execution logs and Orchestrator queue items from the customer's environment and sends them to Anthropic's Claude API for analysis. These payloads may contain personal data present in the customer's automation workflows — for example, names, identifiers, or addresses contained within queue item bodies.

Controls that apply to this mode:

Shared controls

Customer responsibility

Because AriA's transaction-level analysis retrieves data already present in the customer's UiPath environment, the customer remains responsible for the legal basis under which that data is collected and processed. Customers should ensure that their use of AriA is consistent with their own data protection notices, lawful bases, and internal policies, and that their Authorized Users are appropriately restricted where transaction data contains sensitive personal data.

Compliance & Certifications

FrameworkStatusTarget
GDPRCompliant — DPA available on request, EU data residency, EU-registered legal entityOngoing
SOC 2 Type IIn progressQ3 2026
SOC 2 Type IIPlanned — observation window begins at Type I issuanceQ1 2027
ISO/IEC 27001:2022In progressQ4 2026
ISO/IEC 42001 (AI Management System)Roadmap2027

Security questionnaires. We maintain a pre-filled SIG Lite response for customer procurement teams. Request a copy at security@roqaai.com.

Subprocessors

We use a small number of subprocessors to operate ROQA AI. Each subprocessor is bound by a data processing agreement and appropriate safeguards.

SubprocessorPurposeLocationCertifications
Microsoft AzureCloud infrastructure (compute, storage, database)EUISO 27001, SOC 2 Type II
Anthropic, PBCLLM inference for AriA via Anthropic's Claude API — including sensitive data analysis, on-demand transaction-level analysis, and lightweight conversational tasksUS (zero-retention API, SCCs in place)SOC 2 Type II, ISO 42001
Microsoft 365 (Exchange Online)Transactional emailUSISO 27001, SOC 2 Type II

We notify customers at least 30 days before adding new subprocessors. To subscribe to subprocessor change notifications, email security@roqaai.com.

Data Handling & Privacy

Customer data we process by default:

Customer data we process on user request:

Customer data we do not process:

Data retention: Operational telemetry is retained for 30 days by default, configurable by the customer. AriA chat context is retained for 1 hour idle or 10 messages. AriA generated files are ephemeral, with a maximum retention period of 24 hours. Transaction-level payloads retrieved for on-demand analysis are not persisted in ROQA AI's systems beyond the duration of the user's analysis session.

Data deletion: On termination of a customer agreement, all customer data is deleted within 30 days, or exported at customer request.

Data subject rights: As a GDPR processor, ROQA AI supports customer requests to access, correct, or delete personal data of their end users. Requests can be made to privacy@roqaai.com.

Incident Response

ROQA AI maintains a documented incident response plan covering detection, containment, eradication, recovery, and post-incident review. In the event of a security incident involving customer data:

Report a suspected vulnerability or incident: security@roqaai.com

Business Continuity

Legal Entity

SYNC DEV AUTOMATIONS SRL
11 Frunzei St., Galati, Galati, Romania
RO41565673
Romania

Contact

PurposeEmail
Security inquiries, vulnerability reportssecurity@roqaai.com
Privacy, GDPR, data subject requestsprivacy@roqaai.com
Procurement, DPA, questionnairestrust@roqaai.com