Our entire product depends on your people telling their coach the truth. They only do that if the privacy holds — so we built it as architecture, not policy. This page says exactly where every line sits.
Row-level security at the database. Access rules are enforced by the database engine itself on every query — the way a bank separates accounts. A manager's login structurally cannot return a report's private conversations; an investor-side login structurally cannot return anything individual. It is not a policy someone follows. It is a wall the system cannot cross.
Organization isolation. Every client organization's data is siloed at the database level. There are no cross-organization reads, period.
Admin-invite only. There is no self-serve signup. Every account is created deliberately, by your facilitator, for a named person in your organization.
No AI training. Ever. Nothing your team writes or says trains any AI model. Your organization's data makes your coach smarter about your team — and goes nowhere else.
SOC 2–certified infrastructure. The platform runs end-to-end on SOC 2 Type II–certified vendors, with US data residency, encryption in transit and at rest, and full audit logging.
The exit promise. Leave at any year-end and receive a complete export of everything your team built — then we purge it. Your data is never the hostage. The reason clients stay is what the system knows, not what it holds.
Ask, and we show you — literally — the report your leadership (or your investor) receives. One page of aggregates. Every client, every prospect, every skeptical founder gets the same offer, because the fastest way to trust the wall is to see both sides of it.
Questions about any of this — including the specific enforcement details — are welcome: start a conversation and ask for the security walkthrough.