Security & Data Protection
How CoachOps.ai protects coach and client data.
CoachOps.ai is preparing for a SOC 2 (Security, Availability, Confidentiality) audit. We have not yet engaged an auditor and hold no SOC 2 report today — the controls below are in place and independently verifiable in our source code, not certified by a third party. We will update this page the moment that changes.
Tenant Isolation
Every coach and team's data is scoped at the database layer, not just in the application UI. Every query is enforced against a tenant identifier before it can return a result, so one coach's data cannot be read by another.
Encryption
Data is encrypted at rest and in transit in MongoDB Atlas. Third-party integration credentials are encrypted before storage. All connections to the Service use HTTPS.
Private File Storage
Uploaded and generated files are never made public. Access is granted only through short-lived, signed URLs issued to an authenticated, authorized user.
Access Control
Multi-factor authentication is enforced on the accounts we use to administer production infrastructure. Role-based access controls govern what a coach, administrator, or oversight user can view or change within the platform.
Incident Response and Recovery
We maintain a documented incident response procedure and disaster recovery plan, with a target recovery time objective (RTO) of 8 hours and a target recovery point objective (RPO) of 1 hour.
AI Processing
Anthropic is our sole AI provider. Session content is sent to Anthropic for processing but is not used to train their models. See our Privacy Policy for the full list of subprocessors.
Questions
For security questions, including requests for our current compliance documentation, contact hello@coachops.ai.