Rooky exists to confirm that a person is who they claim to be. That only works if the service itself can be trusted, so this page collects what security and procurement teams usually need in one place. If you need something that is not here, our security team will answer directly.
1. How Rooky is designed
Verification runs on a path that is separate from the call, message, or meeting in question. A confirmation comes from the claimed person’s own trusted device, so an attacker who controls the original channel cannot produce one.
- Trusted device identity. Approvals are bound to a device that has been enrolled by the account holder.
- Short-lived requests. Verification requests expire quickly, so a confirmation is tied to the moment it was asked for.
- Biometric confirmation. An additional personal check is available for higher-risk approvals.
- Encryption in transit and at rest. Traffic to Rooky uses TLS, and stored data is encrypted at rest.
2. What we do not do
Some of the strongest guarantees we can offer are about data we never take in the first place.
- We do not record the content of your calls, messages, or meetings.
- We do not upload your address book to build or sell a contact directory.
- We do not sell personal information.
The full detail of what we do collect, why, and for how long is set out in our Privacy Policy.
3. Compliance and certifications
Rooky is an early-stage company and does not yet hold a completed SOC 2 or ISO 27001 certification. We build against those frameworks and will publish reports here once audits are complete. We would rather tell you that plainly than imply coverage we do not have.
If your organization needs a security review before adopting Rooky, contact us and we will work through your questionnaire and share the documentation we have available under NDA.
4. Reporting a vulnerability
If you believe you have found a security vulnerability in Rooky, please report it to us before disclosing it publicly. Include enough detail to reproduce the issue, and we will acknowledge your report and keep you updated while we investigate.
We will not pursue legal action against researchers who report in good faith, avoid privacy violations and service disruption, and give us a reasonable opportunity to fix the issue.
5. Documentation
- Privacy Policy — what we collect, why, and your choices.
- Terms of Service — the terms that govern use of Rooky.
- Security and privacy overview — how verification protects you in practice.
6. Contact our security team
Security questions, vulnerability reports, and vendor security questionnaires all reach us at the address below.
Talk to our security team
We answer vulnerability reports, security questionnaires, and questions about how Rooky handles data.