Security
Your data, protected
CoachOS handles sensitive health and fitness data. We take security seriously and build protection into every layer of the platform.
Encryption
Data is protected using industry-standard encryption in transit and at rest. Sensitive credentials and connection tokens receive additional protection where appropriate.
Authentication
Passwords are securely hashed, authenticated sessions are protected and time-limited, and supported integrations use established authorization standards.
Infrastructure
Production services use established cloud providers, isolated environments, restricted administrative access, encrypted connections, and automated backup and recovery controls.
Access Controls
Role-based permissions separate client, coach, and team access. Protected services apply authentication and authorisation controls before returning account data.
Monitoring
Operational errors, performance, and relevant security events are monitored and investigated so that potential problems can be identified and addressed.
Incident Response
Documented incident response procedures guide investigation, containment, recovery, and notification. Where legally required, we notify the ICO within the applicable timeframe and affected people without undue delay.
Compliance
Privacy and platform obligations
CoachOS is designed to comply with UK GDPR and the Data Protection Act 2018. We process health data as special category data with explicit user consent and apply enhanced safeguards.
- UK GDPR: Designed to support data subject rights, lawful processing, accountability, and appropriate privacy risk assessments.
- Health Data: Special category data handling with explicit consent, encryption, and strict access controls.
- Apple HealthKit: HealthKit data is not used for advertising or sold to third parties and is handled in line with Apple's platform requirements.
- Google Health Connect: Health Connect data is used solely for displaying fitness metrics and sharing with assigned coaches.
- Payment Security: All payments are processed by Stripe, a PCI DSS Level 1 certified provider. CoachOS never stores card details.
Responsible Disclosure
If you discover a security vulnerability, please report it responsibly. We appreciate the security research community and will acknowledge valid reports.
hello@coachos.io