CoffeePals

Security

Enterprise-grade security,
built in from day one.

CoffeePals is SOC 2 Type 2 audited and Microsoft 365 certified. We partner exclusively with cloud providers meeting SOC 2, ISO 27001, and PCI-DSS standards — so your data is protected at every layer.

SOC 2 Type 2 CompliantMicrosoft 365 Certified

How we protect your data

Security isn't an afterthought — it's embedded in every layer of our platform.

Data Encryption

All data is encrypted in transit with TLS 1.3+ and at rest with AES-256. Stored across multiple AWS regions in the United States.

Limited Data Access

CoffeePals only receives messages sent directly to the bot. We have zero access to private messages, group chats, or channel conversations.

Cloud Infrastructure

Hosted on AWS through providers certified for SOC 2, ISO 27001, and PCI-DSS. Physical security managed by AWS across multiple data centers.

Access Control

Least-privilege access for every team member. Deny-by-default policy. Multi-factor authentication required across all internal services.

Secure Development

Every feature undergoes code review, automated testing, and OWASP Top 10 review. Production releases require pull request approval from senior staff.

Incident Response

Security issues are our top priority. In compliance with GDPR, affected customers are notified within 72 hours of any incident detection.

Vendor Management

Every vendor is assessed against our formal risk evaluation policy before being granted access to any customer data. See our current subprocessors; customers are notified whenever one is added or removed.

SSO & Authentication

Passwordless authentication by default. Enterprise SSO available via Azure AD. Login tokens expire after one hour.

Need more detail?

We're happy to share our security policies and documentation under NDA. Talk to our team.

For vulnerability disclosures, email security@coffeepals.com