RoundOps
Security
Last updated: 17 August 2026
Security at RoundOps
RoundOps is designed to protect business, customer and payment-workflow information through layered technical and operational controls.
Security controls
- Tenant-scoped access controls designed to keep one business's records separate from another's.
- Role and capability checks for owner, team and sensitive finance actions.
- Encryption for stored provider secrets and secure transport over HTTPS.
- Audit history for important changes and provider events.
- Signed webhook validation and duplicate-event protection for supported integrations.
- Session, device and mobile-token controls.
- Backup, recovery and release-validation procedures.
- Automated source, dependency and security checks as part of release preparation.
Reporting a security issue
If you believe you have found a security vulnerability, please contact our contact page and include enough information for us to reproduce the issue. Do not access, change or download data that does not belong to you.
Responsible disclosure
We ask researchers to act in good faith, avoid privacy violations or service disruption and allow reasonable time for investigation before public disclosure.