Security
Is it secure?
Here's exactly where we are, what we're working towards, and when. We'd rather show you an honest roadmap than a wall of badges.
ISO 27001
In progressUK & EU GDPR
In place todayEU AI Act
In place todaySOC 2
PlannedNo model training
In place todayCertification roadmap
The standards enterprise buyers ask us about, and the current status of each. This page is kept up to date as we progress.
ISO 27001
The international standard for information security management. Our policies and controls are being built to the standard ahead of formal certification.
In progress — target [QX 202X]SOC 2
Independent audit of security, availability, and confidentiality controls, most commonly requested by US enterprise buyers.
Planned — target [QX 202X]HIPAA
Relevant for US organisations in healthcare. On our radar for when we serve customers who require it.
Under evaluationUK GDPR & EU GDPR
We operate under UK and EU data protection law today. All user data is processed and stored on servers within the European Union.
In place todayThe regulations that shape how we build
AI coaching sits across data protection, AI regulation, consumer rights, and professional ethics. Here's the full framework we build to.
Data protection
UK GDPR & Data Protection Act 2018
Our legal foundation in the UK. Personal data is processed lawfully, stored within the EU, and conversations are separated from identities.
Data protection
EU GDPR
The same protections extended to every user in the European Union, backed by data processing agreements with our providers.
Electronic privacy
PECR
The Privacy and Electronic Communications Regulations govern how we handle cookies, analytics, and any direct marketing — consent-first, always.
AI regulation
EU AI Act
The EU's risk-based framework for AI systems, phasing in through 2026 and beyond. We build our architecture to meet its requirements as they take effect.
Consumer rights
Consumer Rights Act 2015
Clear, fair terms for every subscriber — transparent pricing, honest descriptions, and straightforward cancellation.
Accessibility
WCAG 2.2
We build to the Web Content Accessibility Guidelines so coaching is usable by as many people as possible, regardless of ability.
Professional ethics
ICF Code of Ethics
Every coach is built to adhere to the ethical standards that govern professional human coaches, with clear boundaries on scope.
Privacy by design
Data protection by design
The GDPR principle that privacy is engineered in from the start. It's why we collect minimal data and hold conversations without identifiers attached.
What's already in place
Certification takes time. Good practice doesn't have to wait for it.
EU-only data storage
All personal data is processed and stored on servers located within the European Union. No exceptions, no offshore replication.
Vetted processors
Our AI and cloud providers act as data processors under contract — they process data only on our instructions, under appropriate data protection safeguards.
Minimal data by design
We collect only what the service needs to run. The less we hold, the less there is to secure. See our Data page for exactly what that means.
Regular review
Technical and organisational safeguards are reviewed on an ongoing basis, not once a year for an audit.
Where we're going
Our security roadmap, in the open.
-
Now
ISO 27001 groundwork
Information security management system, policy set, and control framework being built to the standard.
-
[QX 202X]
ISO 27001 certification audit
Formal external audit and certification.
-
[QX 202X]
SOC 2 Type I
Independent attestation of our control design, followed by Type II over an observation period.
-
Ongoing
Standards driven by our customers
Where an enterprise customer needs a specific standard, we build it into the roadmap. Tell us what your procurement process requires.
Have a security questionnaire?
We answer procurement and infosec questionnaires directly. Send it over and we'll come back to you with straight answers, including on anything we don't have yet.
Get in touch