Mobile Coach, LLC is committed to the security of our users’ data. Our security-first approach is fundamental to our business. Our company is committed to providing and maintaining the level of Quality and Information Security that meets all of our stakeholders’ needs.
We implement security procedures at all the levels described in this document.
Yearly Information security and data privacy training is mandatory for all employees and contractors. This training includes information about policies and procedures, and provides a reminder on the process to report security incidents.
All newly hired employees have to participate in a mandatory information security training as part of their onboarding. Mobile Coach employees are required to comply with the information security policies that are regularly reviewed. The awareness is checked through regular internal audits.
Mobile Coach LLC complies with the General Data Protection Regulation (GDPR) and adheres to the set of data protection principles in the ISO 27001:2018 standard.
We have in place contractual clauses with subsidiaries and providers that perform data processing outside Europe. Learn more in our statement of data privacy.
Mobile Coach employees and contractors are required to sign a code of conduct and a confidentiality clause as part of their employment contract prior to access to our platform. The clause prohibits any disclosures of confidential information concerning the business of Mobile Coach and its customers. The obligations and duties remain in force after termination.
Mobile Coach is running scheduled backups, to ensure that customer data is both backed up and available on geographically dispersed locations, physically separated from the primary Mobile Coach storage, aiming to ensure recovery.
Access to production infrastructure is granted to a limited number of senior personnel. Mobile Coach uses RBAC and follows the principles of need-to-know and least-privilege in enforcing its access matrix. All access to infrastructure resources is logged and is subject to periodic audits.
We take steps to develop and test against security threats to ensure the information security of our customer data.
Mobile Coach’s Software Development Life Cycle (SDLC) includes several stages to ensure that changes are documented, implemented on a source controlled version of the code, reviewed and tested against the acceptance criteria. Releases to each environment must happen through a controlled process.
In addition to our internal scanning and testing, we periodically undergo third-party black box penetration tests on all our services (infrastructure & application).
Each user with access to the Mobile Coach Platform has a unique account with a verified email address, and protected with a password, which are validated against strong password policies and stored securely using a strong hashing algorithm for every password.
Communications with Mobile Coach services are encrypted via industry best-practices HTTPS and Transport Layer Security (TLS 1.2 at least) over public networks. We use public trusted digital certificates, signed by an authorized Certificate Authority.
All customers of Mobile Coach benefit from the protections of encryption at rest for the storage layer.
Each customer’s data are stored in a segregated container.
Customer data shared with Mobile Coach for the purposes of engaging users via a chatbot are never shared.
Learn how Mobile Coach chatbots will help you drive real engagement with your audience to achieve the key behaviors and results you want.