Security by architecture.
Roster runs inside your infrastructure and resolves against the directories you already trust.
Directory data, platform configuration and operational records remain in the systems you control. Roster does not replicate them to an Advantys-operated cloud.
The model in one line
Roster is self-hosted and does not phone home.
It reads selected directory data, resolves who should act using the model provider you configure, and stores the resulting operational data inside your deployment.
There is no Roster-operated cloud holding your directory records, resolution history or configuration. When you select an external model provider, data sent to that provider is governed by your configuration and agreement with that provider.
Data residency & isolation
Choose the deployment shape that matches your infrastructure — Roster keeps its data where you put it.
How Roster handles directory data
Minimal collection, targeted synchronization, encrypted secrets — the connector layer is built for least-data.
Authentication & access control
SSO through your IdP, scoped keys, and role-aware ownership — no shared admin accounts.
Audit & observability
Explainable history for every decision — attributable, retained on your terms.
Privacy & data minimization
Field-level PII controls applied at write time — not just at display.
Database security
SQLite for standalone, PostgreSQL for Enterprise — with role separation and connection controls.
High availability
Roster High Availability has two independent layers behind a common configuration.
- Two or more identical Roster instances behind a load balancer
- PostgreSQL with a writable primary and at least one read replica
Every Roster instance uses the same public authentication URL, authentication secret, provider-encryption secret, database endpoints, runtime configuration and Enterprise license.
- Load-balancer redundancy
- PostgreSQL replication
- Failure detection
- Primary promotion
- Stable writer and read-only endpoints
- Backups and point-in-time recovery
- Replica health and replication-lag monitoring
Roster validates HA mode uses PostgreSQL and required configuration, but does not operate or independently verify the cluster topology.
Compliance & operations
Roster slots into the security, retention and residency controls you already operate — plus a documented backup and recovery path.
Built by Advantys, makers of WorkflowGen — process automation trusted in production since 2003.
Reporting a vulnerability
Found a potential security issue? Email security@advantys.com. We welcome responsible disclosure and will acknowledge your report.