Version 3 · Effective 2026-08-15

This document is a draft and has not yet been reviewed by legal counsel. It is not yet in effect.

Security Policy

Version: 3 · Last revised: August 15, 2026 · not yet in effect — see the notice above

This Security Policy describes, at a summary level, how Coachstra protects Customer Data. It is written for prospective and current customers evaluating Coachstra, and is consistent with — but less formal than — the Technical and Organisational Measures annexed to our Data Processing Agreement and our fuller Technical & Organisational Measures document.

Encryption

Data is encrypted in transit using TLS on every connection. Data at rest is encrypted via our infrastructure provider's encryption-at-rest capability.

Access control

Every coach's data is scoped to that coach's own practice through row-level access controls; one coach cannot query another coach's data. A separate, more restrictive access tier for sponsor/aggregate reporting roles — unable to reach individual session content or notes under any circumstance — is planned but not yet built; the Sponsor role is not part of the current release.

Consent-gated processing

Recording, transcription, and AI analysis are blocked at the server layer until the relevant consent has been captured — this is enforced independently of the user interface, so it cannot be bypassed by a modified client.

Logging and monitoring

Access to recordings, transcripts, and session notes is logged.

Monitoring of those logs is manual today, not automated. We do not yet run automated alerting on access patterns, and we have not set a formal log retention period. We will state both here once automated monitoring is in place; until then this section describes what exists rather than what we intend.

Backups and disaster recovery

Coachstra relies on the managed backup facilities of its database platform rather than operating its own backup schedule. Those backups cover the database only. Files held in object storage — session recordings, signed contracts, receipts, uploaded documents and profile images — are not covered by them; the platform offers no backup and no versioning for stored objects at any service tier, and deleting one is immediate and irreversible. We would rather say so than let "managed backup facilities" imply a protection that does not extend to those files.

We have not yet defined or tested a recovery time objective or recovery point objective, and we do not claim one. Both will be stated here, and in the Data Processing Agreement's Annex 2, once they have been set and a restore has actually been rehearsed — not before.

Personnel

Access to production systems and Customer Data is limited to personnel who need it to operate the Service, each bound by confidentiality obligations.

Vulnerability and incident handling

Our approach to security incidents, including detection and customer notification, is described in our Incident Response Policy.

Certifications

Coachstra does not hold SOC 2, ISO 27001, or any other formal security certification, and does not claim to. We would rather say so plainly than imply otherwise through vague wording.

Our infrastructure providers hold their own certifications, but those are theirs and are not transferable to us. We will revisit certification when there is a concrete reason to — an enterprise agreement that requires it — rather than pursuing one speculatively.

Reporting a security issue

If you believe you've found a security vulnerability, contact info@coachstra.com.


This document is a draft describing our security posture as understood at the time of writing. It is not a warranty and must be verified against actual infrastructure configuration before publishing.