Trust by Architecture

Security isn't a feature.
It's the foundation.

We don't just promise privacy—we build it into every layer. Your data is encrypted, siloed, and never used to train AI models. Period.

Trust Hierarchy

Our security model is built on layers—each one independent and verifiable.

Architecture Trust

  • Per-tenant encryption — each organization gets dedicated keys (AWS KMS), AES-256-GCM at rest
  • Governed access — every read is role-restricted, least-privilege, and audit-logged
  • Isolated data stores — each coach's data is completely separate
  • Automatic data expiration — recordings auto-delete, transcripts persist

Certification Trust

  • SOC 2 Type II — architected from day one, certification in progress
  • HIPAA-ready — designed for healthcare coaching contexts from the start
  • GDPR — built to EU data protection standards with full portability and deletion rights
  • Regular penetration testing — by independent security firms

Privacy-Tiered, Governed Access

You decide who sees what through privacy tiers. Data is encrypted per tenant, and AI processing is service-bounded — every access is role-restricted, least-privilege, and audit-logged.

YOU

Your Controls

You set the privacy tier for every item — who can see individual vs. aggregate data.

You control access
SERVER

Our Servers

Encrypted per tenant at rest (AES-256-GCM); access is role-restricted and logged.

Governed access
AI

AI Processing

Ephemeral. Never retained. Never used for training.

Deleted after use

What We Never Send to AI

Some data is too sensitive for any AI processing. These categories are never sent to language models—ever.

Credentials & passwordsNever
Credit card numbersNever
Social Security numbersNever
Medical record numbersNever
Tier 1 private conversationsNever
Precise location dataNever
Authentication tokensNever
Financial account numbersNever

Compliance Coverage

Same security at every tier. No exceptions.

GDPR

European Union

Designed to standard

SOC 2

Global

In progress

HIPAA

United States

Readiness in progress

CCPA

California

Designed to standard

The Evaporation Promise

When you delete your data, it's gone—not archived, not 'anonymized,' not kept for training. Gone means gone.

Export First

Download all your data in standard formats before deletion

Complete Removal

All data, all backups, all traces—permanently erased

30-Day Grace

Changed your mind? Restore within 30 days

FOR SECURITY & IT TEAMS

Enterprise Security Architecture

Deep technical documentation for security teams, compliance officers, and IT leadership. Click any section to expand.

Want the full engineering blueprint?

Our complete security architecture documentation covers every layer—legal, enterprise, and product—with interactive diagrams, compliance matrices, and architectural decision records.

View full security architecture

53 pages · 3 architecture layers · Interactive diagrams

Ready to experience trust by architecture?

Security is the same at every tier. No enterprise lock-in required.

View Pricing