Declarative by design
Reviewers document agents, tools, permissions and safeguards without connecting audited-tool OAuth accounts.
Roxea is a declarative review tool. This page explains what the product needs, what it does not access, and which operational details are currently public.
Last reviewed: July 5, 2026
Reviewers document agents, tools, permissions and safeguards without connecting audited-tool OAuth accounts.
The Roxea service is deployed with OVH, whose registered hosting address is in Roubaix, France.
Roxea uses authenticated accounts, hashed passwords, verified Google ID tokens when selected, and organization-scoped roles.
You choose the names and descriptions you record. Production credentials and business-content copies are not required.
Service providers
These providers support hosting, billing, authentication, analytics and transactional email. Optional services only apply when you choose or consent to them.
| Provider | Purpose | Relevant data |
|---|---|---|
| OVHcloud | Application and database hosting | Account and workspace data required to provide Roxea |
| Stripe | Subscription and billing | Billing contact, subscription and payment metadata; card data stays with Stripe |
| Optional Google Sign-In and consented analytics | Verified identity token for sign-in; public-site usage only after analytics consent | |
| Brevo | Transactional email | Recipient, subject and delivery information needed for account emails |
Account and workspace data is retained while the service is active. Billing records follow legal accounting obligations, while security and troubleshooting logs are retained for a limited period. Deletion requests can be sent to rgpd@roxea.app.
Read the Privacy PolicyRoxea does not publish unverified claims about encryption at rest, backup schedules, recovery targets, deletion SLAs or DPA availability. Ask for the current operational details before using the service with sensitive client information.
Contact contact@roxea.appA Roxea report records declared access and recommended follow-up. It is not a penetration test, runtime monitor, compliance certificate or independent assurance engagement.