Security — build blocks

Security

Is it secure?

Here's exactly where we are, what we're working towards, and when. We'd rather show you an honest roadmap than a wall of badges.

ISO 27001

ISO 27001

In progress
UK & EU GDPR

UK & EU GDPR

In place today
EU AI Act

EU AI Act

In place today
SOC 2

SOC 2

Planned

No model training

In place today

Certification roadmap

The standards enterprise buyers ask us about, and the current status of each. This page is kept up to date as we progress.

ISO 27001

The international standard for information security management. Our policies and controls are being built to the standard ahead of formal certification.

In progress — target [QX 202X]

SOC 2

Independent audit of security, availability, and confidentiality controls, most commonly requested by US enterprise buyers.

Planned — target [QX 202X]

HIPAA

Relevant for US organisations in healthcare. On our radar for when we serve customers who require it.

Under evaluation

UK GDPR & EU GDPR

We operate under UK and EU data protection law today. All user data is processed and stored on servers within the European Union.

In place today

The regulations that shape how we build

AI coaching sits across data protection, AI regulation, consumer rights, and professional ethics. Here's the full framework we build to.

Data protection

UK GDPR & Data Protection Act 2018

Our legal foundation in the UK. Personal data is processed lawfully, stored within the EU, and conversations are separated from identities.

Data protection

EU GDPR

The same protections extended to every user in the European Union, backed by data processing agreements with our providers.

Electronic privacy

PECR

The Privacy and Electronic Communications Regulations govern how we handle cookies, analytics, and any direct marketing — consent-first, always.

AI regulation

EU AI Act

The EU's risk-based framework for AI systems, phasing in through 2026 and beyond. We build our architecture to meet its requirements as they take effect.

Consumer rights

Consumer Rights Act 2015

Clear, fair terms for every subscriber — transparent pricing, honest descriptions, and straightforward cancellation.

Accessibility

WCAG 2.2

We build to the Web Content Accessibility Guidelines so coaching is usable by as many people as possible, regardless of ability.

Professional ethics

ICF Code of Ethics

Every coach is built to adhere to the ethical standards that govern professional human coaches, with clear boundaries on scope.

Privacy by design

Data protection by design

The GDPR principle that privacy is engineered in from the start. It's why we collect minimal data and hold conversations without identifiers attached.

What's already in place

Certification takes time. Good practice doesn't have to wait for it.

EU-only data storage

All personal data is processed and stored on servers located within the European Union. No exceptions, no offshore replication.

Vetted processors

Our AI and cloud providers act as data processors under contract — they process data only on our instructions, under appropriate data protection safeguards.

Minimal data by design

We collect only what the service needs to run. The less we hold, the less there is to secure. See our Data page for exactly what that means.

Regular review

Technical and organisational safeguards are reviewed on an ongoing basis, not once a year for an audit.

Where we're going

Our security roadmap, in the open.

  • Now

    ISO 27001 groundwork

    Information security management system, policy set, and control framework being built to the standard.

  • [QX 202X]

    ISO 27001 certification audit

    Formal external audit and certification.

  • [QX 202X]

    SOC 2 Type I

    Independent attestation of our control design, followed by Type II over an observation period.

  • Ongoing

    Standards driven by our customers

    Where an enterprise customer needs a specific standard, we build it into the roadmap. Tell us what your procurement process requires.

Have a security questionnaire?

We answer procurement and infosec questionnaires directly. Send it over and we'll come back to you with straight answers, including on anything we don't have yet.

Get in touch