Trust center

Security and data handling, without vague promises.

Roxea is a declarative review tool. This page explains what the product needs, what it does not access, and which operational details are currently public.

Last reviewed: July 5, 2026

Declarative by design

Reviewers document agents, tools, permissions and safeguards without connecting audited-tool OAuth accounts.

Hosted in France

The Roxea service is deployed with OVH, whose registered hosting address is in Roubaix, France.

Protected accounts

Roxea uses authenticated accounts, hashed passwords, verified Google ID tokens when selected, and organization-scoped roles.

Minimal review data

You choose the names and descriptions you record. Production credentials and business-content copies are not required.

Information Roxea uses

  • Account and organization details
  • Agent names, owners, purpose and autonomy
  • Declared tools, permissions and safeguards
  • Generated findings, actions and reports

Information the review does not require

  • OAuth tokens for Gmail, Slack, HubSpot, Stripe, GitHub or other audited tools
  • API keys, production credentials or customer-system passwords
  • Copies of emails, chats, transactions, source code or documents
  • Continuous runtime access to discover or monitor agents

Service providers

Subprocessors used to operate Roxea

These providers support hosting, billing, authentication, analytics and transactional email. Optional services only apply when you choose or consent to them.

ProviderPurposeRelevant data
OVHcloudApplication and database hostingAccount and workspace data required to provide Roxea
StripeSubscription and billingBilling contact, subscription and payment metadata; card data stays with Stripe
GoogleOptional Google Sign-In and consented analyticsVerified identity token for sign-in; public-site usage only after analytics consent
BrevoTransactional emailRecipient, subject and delivery information needed for account emails

Retention and deletion

Account and workspace data is retained while the service is active. Billing records follow legal accounting obligations, while security and troubleshooting logs are retained for a limited period. Deletion requests can be sent to rgpd@roxea.app.

Read the Privacy Policy

Details available on request

Roxea does not publish unverified claims about encryption at rest, backup schedules, recovery targets, deletion SLAs or DPA availability. Ask for the current operational details before using the service with sensitive client information.

Contact contact@roxea.app

Scope matters as much as the score.

A Roxea report records declared access and recommended follow-up. It is not a penetration test, runtime monitor, compliance certificate or independent assurance engagement.

Ask a security question