Security

  • Data encryption in transit
    • Data encrypted at rest using AES-256 encryption
  • Access controls & role-based permissions
    • immediate access revocation/ off-boarding controls
    • Principle of least privilege
  • Secure authentication
  • Regular security test / reviews
  • Backup & disaster recovery approach
  • User enumeration
  • Application security protections (SQL Injection & form input restrictions)
  • Formal risk management
  • Secure SDLC
  • Continuous monitoring & alerts
  • Annual third-party testing/ pentests

Compliance & Regulations

  • GDPR Compliance statement
  • Data processing agreements (available on request)
  • Planned certifications (ISO27001, SOC2)
  • Regional data handling commitments

Privacy & Data Collection

  • What data we collect
  • Why we collect it
  • How long it is retained for
  • Who can access it
  • Links to privacy policy
  • GDPR right to be forgotten + data export controls

AI & Data Usage

  • Is coaching data isolated per customer?
  • Is data used to train models?
  • Human access boundaries
  • Safeguards & monitoring

Policies & Documentation

  • Information security policy
  • Access control policy
  • Incident response policy
  • Data protection policy
  • Acceptable/ fair usage policy
  • Background checks for staff

Infrastructure & Hosting

  • Cloud providers
  • Data storage locations
  • High-level architecture
  • Availability and resilience basics
  • Business continuity/ disaster recovery

Incident Response

  • How are incidents detected?
  • Response timelines
  • Customer notification process
  • Post-incident reviews
  • Incident response plan/ playbook

Third-Party Sub-processors

  • Cloud providers
  • AI providers
  • Analytical tools (if any)
  • What each of these are used for
  • Security review of third party sub processors

Contact & Responsible Disclosure

  • Security contact email
  • How to report vulnerabilities
  • Response expectations