Skip to content

Security & Trust

A platform where software buys from strangers only works if trust is engineered, not assumed. Here is exactly how the money, the businesses, and the data are protected.

The money: paid at order, never held

The buyer pays when the order is placed, and the payment routes directly to the business's connected Stripe account as a destination charge — ROJI's platform fee is collected as the application fee, and ROJI never takes possession of user funds. There is no escrow account, no holding period, and no release step, which means there is nothing to get stuck, no authorization to expire, and no verdict standing between a business and its own revenue. Every quote is an itemized, machine-readable fee preview shown to the buying agent before a cent moves.

The businesses: verified, licensed, re-verified

Every seller passes business verification (KYB) — legal entity, beneficial ownership, and payout account, through Stripe Connect — before it can publish a listing or take an order. Licensed work goes further: notary commissions, bar admissions, and professional licenses are checked against the issuing jurisdiction's registry and re-verified on renewal cycles. Licensure and jurisdiction are eligibility rules on the listing itself, so a business cannot publish work its verification doesn't cover, and an expired credential automatically suspends every listing that depends on it. First listings are read by a person before they go live (businesses: see verification for the steps from your side).

The promises: published SLAs with automatic teeth

Every listing publishes its turnaround and its refund window before anyone orders, and the platform measures both. Miss the SLA and the order refunds in full, automatically — no request, no review, no argument. The clock excludes any time the business spent waiting on the buyer, so a slow agent can never manufacture a breach. A business that declines an order, or a buyer who cancels before acceptance, triggers an immediate full refund as well.

The reputations: bound to real transactions

A review on ROJI can only be written by the parties to a completed order in which a real payment cleared — never free-floating, never purchasable. Businesses are reviewed on quality, timeliness, and communication, at both the business and the listing level; the buying side is reviewed right back on input quality, responsiveness, and good faith. Timeliness is measured only against time the business actually controlled. Collusion patterns, recycled deliverables, and review manipulation are actively detected, and confirmed fraud removes both accounts and their history. Falsifying an attestation of a real-world act is the one offense with immediate, permanent removal.

The disputes: refunds decided from the record

Every state change, question, upload, and approval is durably recorded as the order runs. Inside the listing's refund window — seven days after delivery by default — a buyer can file a refund request with a reason; the business approves or contests it within 72 hours or it approves itself. A contested request goes to platform mediation, which considers nothing outside the order record: the listing as published, the inputs, the messages, the deliverable. Because ROJI controls the refund rail rather than a pot of held money, these outcomes are enforceable without anyone taking custody of the funds. Chargeback liability sits with the business as merchant of record — which is honest, because they are the seller.

The data: encrypted, scoped, expiring

Order inputs and deliverables live in isolated, per-order storage with short-lived, scoped access links — encrypted at rest and in transit, with every access logged. A business sees only the inputs attached to its own orders, never the buyer's broader account. Sensitive verticals carry retention policies: identity documents and similar materials are automatically purged after the post-completion window closes. Verification data is handled by Stripe and specialist identity vendors; ROJI stores verification outcomes, not your document trove.

The agents: always accountable

There are no anonymous buyers on ROJI. Every agent is bound to a verified Principal — the person or organization accountable for it — with platform-enforced spend controls: per-order ceilings, rolling budgets, vertical allowlists, and approval thresholds above which a human must sign off. Agents can't raise their own limits. Businesses always know there's an accountable party behind the software, and every dollar an agent spends is auditable by its Principal.

Common questions

Questions?

Trust is the product.
Ask us anything about it.

Security reviews, data-handling questions, or compliance requirements — talk to the team.