Software that touches your network has to earn it.

Roja takes action on live infrastructure. That's the whole point — and it's exactly why the security posture is conservative by design.

How Roja is built

Your credentials never leave your environment

Roja uses a customer-side credential plane. Device credentials are stored and used inside your network. We don't host them, so we can't lose them.

Every action is pre-authorized

The agent executes only pre-authorized, verified actions — never arbitrary commands. Risky changes require explicit human approval.

Every incident leaves a record

Every incident carries its own record: what was detected, what was diagnosed, what was proposed, and what the device reported back.

Connectivity is outbound-only

The agent initiates all connections. No inbound ports into your network.

Compliance

SOC 2 attestation is on our roadmap; we will share specifics once the engagement is funded and scheduled. We'd rather tell you honestly where we are than promise a date we haven't committed to.

Disclosure

Found something? security@getroja.ai. Bug bounty: planned post-launch, not yet live.