Trust

Security & data protection

Payroll is the most sensitive data a business holds. This page sets out exactly where RockPay keeps your data and the controls that protect it — in plain language, with no claims we cannot evidence.

Where your data is stored

Hosting region
United Kingdom — AWS eu-west-2 (London).
What is stored there
Company details, employee records, payroll runs, payslips, statutory forms and HR documents — all in the same UK region.
Underlying platform
Managed PostgreSQL, authentication and object storage on AWS infrastructure, which holds ISO 27001 and SOC 2 Type II certification at the infrastructure layer.
Held on your device
Only a session token and interface preferences. No payroll data is cached on your computer.

Controls in place

Company-level data isolation

Every table enforces row-level security in the database itself. A user's session can only ever read or write rows belonging to companies they are a member of — isolation is enforced by the database, not by the user interface, so it cannot be bypassed by manipulating the app in a browser.

Separated roles and least privilege

Company admin, payroll admin and employee permissions are held in a dedicated roles table, never on the user's own profile record, and are evaluated by trusted database functions. This structure prevents a user from granting themselves elevated access. Platform-level administration is a separate, tightly restricted list.

Employee self-service is read-restricted

Staff signing in to the employee portal can see only their own record, payslips and P8 — enforced by database policy for each individual query, not by hiding pages.

Private document storage

HR documents, contracts and uploaded evidence live in a private storage bucket with no public URLs. Files are served only through short-lived, signed links issued to an authorised, authenticated user.

Credential handling

Passwords are salted and hashed by the managed authentication service and are never stored, logged or visible to RockPay. Google single sign-on is supported. Invitations and password resets use single-use, time-limited links. Privileged service keys exist only on the server and are never exposed to the browser.

Encryption everywhere

TLS 1.2+ is enforced for all traffic, including rockpay.co.uk and the application. Data at rest — the database, file storage and backups — is encrypted with AES-256.

Backups and continuity

The platform takes automated daily backups of the database with point-in-time recovery available on the underlying infrastructure. Statutory payroll records remain viewable and exportable even if an account lapses: suspended or past-due accounts move to read-only rather than losing access.

Managed, patched infrastructure

RockPay runs on managed cloud infrastructure with operating system and database patching handled by the provider, removing the risk of an unpatched self-hosted server holding payroll data.

Data protection and your obligations

RockPay is developed and licensed by AM Consultancy (Alejandro Munoz Lopez), business licence BL257697, Gibraltar GX11 1AA. For the employee data you enter, your business is the data controller and RockPay acts as processor, handling that data only to provide the payroll service to you.

Processing is aligned with the Gibraltar Data Protection Act and UK GDPR principles: data is used only to deliver payroll and statutory reporting, is never sold, and is not shared with third parties for marketing. Personal data stays within the UK region described above.

You can export your data at any time in open formats (CSV, PDF and the statutory XML filings), so you are never locked in. On written request we will delete your account data, subject to any retention period you are legally required to observe for payroll records.

We do not claim SOC 2, ISO 27001 or PCI certification for RockPay itself; those certifications are held by the infrastructure providers listed above. If your organisation requires a completed security questionnaire or a data processing agreement, contact us and we will provide one.

Reporting a vulnerability

If you believe you have found a security issue, please report it privately through our contact form rather than publicly. We will acknowledge the report and keep you updated on the fix. Please do not access, modify or download data belonging to other users while investigating.

Need a security review before you switch?

We are happy to walk your IT or compliance team through the setup.

See also our Privacy Policy and Terms of Service.