SECURITY & TRUST

What's said in coaching stays in coaching.

The commitments, the architecture, and the evidence behind them.

Three commitments we hold

What we commit to, and how the architecture enforces it.

Private

Coaching stays between the person and their coach. No company admin can read it. Neither can we.

Read the Privacy Policy →

Encrypted

At rest, in transit, end-to-end encryption on every session. The controls are listed in our trust center.

Read the DPA →

Portable

Coaching follows the person. Their growth travels with them. Company context is purged on departure.

Read the terms →

What we don't do

The questions IT and HR ask us first, answered straight.

Voice audio is never stored

We transcribe what you say, then the audio is gone. There is no recording stored, ever.

Your words never train our models

Coaching conversations are never used as training data. Not for our models, and not for anyone else's.

No back door to a session

No admin dashboard, eDiscovery route, or compliance API can open someone's session. That path does not exist.

Where we stand today

Live status, current documents, and the full sub-processor list all sit in the trust center.

SOC 2

Compliant since June 2026, with controls monitored continuously. Certification is expected soon.

See the controls →

ISO 27001:2022

Our information security management system is built and monitored against the 2022 standard.

See the controls →

GDPR

A signed DPA, a published sub-processor list, and EU data residency on enterprise plans.

Read the DPA →