Security
Enterprise-grade security,
built in from day one.
CoffeePals is SOC 2 Type 2 audited and Microsoft 365 certified. We partner exclusively with cloud providers meeting SOC 2, ISO 27001, and PCI-DSS standards — so your data is protected at every layer.

How we protect your data
Security isn't an afterthought — it's embedded in every layer of our platform.
Data Encryption
All data is encrypted in transit with TLS 1.3+ and at rest with AES-256. Stored across multiple AWS regions in the United States.
Limited Data Access
CoffeePals only receives messages sent directly to the bot. We have zero access to private messages, group chats, or channel conversations.
Cloud Infrastructure
Hosted on AWS through providers certified for SOC 2, ISO 27001, and PCI-DSS. Physical security managed by AWS across multiple data centers.
Access Control
Least-privilege access for every team member. Deny-by-default policy. Multi-factor authentication required across all internal services.
Secure Development
Every feature undergoes code review, automated testing, and OWASP Top 10 review. Production releases require pull request approval from senior staff.
Incident Response
Security issues are our top priority. In compliance with GDPR, affected customers are notified within 72 hours of any incident detection.
Vendor Management
Every vendor is assessed against our formal risk evaluation policy before being granted access to any customer data. See our current subprocessors; customers are notified whenever one is added or removed.
SSO & Authentication
Passwordless authentication by default. Enterprise SSO available via Azure AD. Login tokens expire after one hour.
Need more detail?
We're happy to share our security policies and documentation under NDA. Talk to our team.
For vulnerability disclosures, email security@coffeepals.com