Trust
Security & data protection
Payroll is the most sensitive data a business holds. This page sets out exactly where RockPay keeps your data and the controls that protect it — in plain language, with no claims we cannot evidence.
Where your data is stored
- Hosting region
- United Kingdom — AWS eu-west-2 (London).
- What is stored there
- Company details, employee records, payroll runs, payslips, statutory forms and HR documents — all in the same UK region.
- Underlying platform
- Managed PostgreSQL, authentication and object storage on AWS infrastructure, which holds ISO 27001 and SOC 2 Type II certification at the infrastructure layer.
- Held on your device
- Only a session token and interface preferences. No payroll data is cached on your computer.
Controls in place
Company-level data isolation
Every table enforces row-level security in the database itself. A user's session can only ever read or write rows belonging to companies they are a member of — isolation is enforced by the database, not by the user interface, so it cannot be bypassed by manipulating the app in a browser.
Separated roles and least privilege
Company admin, payroll admin and employee permissions are held in a dedicated roles table, never on the user's own profile record, and are evaluated by trusted database functions. This structure prevents a user from granting themselves elevated access. Platform-level administration is a separate, tightly restricted list.
Employee self-service is read-restricted
Staff signing in to the employee portal can see only their own record, payslips and P8 — enforced by database policy for each individual query, not by hiding pages.
Private document storage
HR documents, contracts and uploaded evidence live in a private storage bucket with no public URLs. Files are served only through short-lived, signed links issued to an authorised, authenticated user.
Credential handling
Passwords are salted and hashed by the managed authentication service and are never stored, logged or visible to RockPay. Google single sign-on is supported. Invitations and password resets use single-use, time-limited links. Privileged service keys exist only on the server and are never exposed to the browser.
Encryption everywhere
TLS 1.2+ is enforced for all traffic, including rockpay.co.uk and the application. Data at rest — the database, file storage and backups — is encrypted with AES-256.
Backups and continuity
The platform takes automated daily backups of the database with point-in-time recovery available on the underlying infrastructure. Statutory payroll records remain viewable and exportable even if an account lapses: suspended or past-due accounts move to read-only rather than losing access.
Managed, patched infrastructure
RockPay runs on managed cloud infrastructure with operating system and database patching handled by the provider, removing the risk of an unpatched self-hosted server holding payroll data.
Data protection and your obligations
RockPay is developed and licensed by AM Consultancy (Alejandro Munoz Lopez), business licence BL257697, Gibraltar GX11 1AA. For the employee data you enter, your business is the data controller and RockPay acts as processor, handling that data only to provide the payroll service to you.
Processing is aligned with the Gibraltar Data Protection Act and UK GDPR principles: data is used only to deliver payroll and statutory reporting, is never sold, and is not shared with third parties for marketing. Personal data stays within the UK region described above.
You can export your data at any time in open formats (CSV, PDF and the statutory XML filings), so you are never locked in. On written request we will delete your account data, subject to any retention period you are legally required to observe for payroll records.
We do not claim SOC 2, ISO 27001 or PCI certification for RockPay itself; those certifications are held by the infrastructure providers listed above. If your organisation requires a completed security questionnaire or a data processing agreement, contact us and we will provide one.
Reporting a vulnerability
If you believe you have found a security issue, please report it privately through our contact form rather than publicly. We will acknowledge the report and keep you updated on the fix. Please do not access, modify or download data belonging to other users while investigating.
Need a security review before you switch?
We are happy to walk your IT or compliance team through the setup.
See also our Privacy Policy and Terms of Service.