Trust
Coaching conversations are confidential, and the platform that stores them has to treat them that way.
This page explains how Coaching Loft protects your data, who can see what inside an account, and what your IT and procurement teams can request from us.
Coaching Loft is based in Dubai. Our servers and offices are located in the United Arab Emirates, and the platform runs on infrastructure from third-party cloud providers that hold SOC 2 Type 2 and ISO 27001 certifications, among others. Those certifications belong to our hosting providers, not to Coaching Loft itself.
Coaching firms and enterprises decide who can sign in and what each person can do once they are in.
The organization that pays for coaching should be able to follow progress without reading the conversations. Coaching Loft is set up that way by default.
You own the data you put into Coaching Loft. We do not sell it, we do not give your email address to other parties for marketing, and we do not use your data to serve you ads.
Coaching firms and enterprises can present Coaching Loft to their coaches and coachees under their own brand.
For a security or procurement review, request our Security Audit Report. It gives an overview of our security practices, compliance measures and infrastructure protections. It is confidential and provided solely for evaluation purposes.
Use the Request our security documentation button on this page to reach the request form. The report covers:
Questions
Coaching Loft itself does not have a published SOC 2 report or ISO 27001 certificate. The cloud providers that host the platform hold SOC 2 Type 2 and ISO 27001 certifications, among others. For your review, our Security Audit Report is available on request. It covers our data protection and encryption standards, access control and authentication methods, GDPR and HIPAA measures, and a cloud compliance report.
Our servers and offices are located in the United Arab Emirates, so information you store in Coaching Loft is transferred to and stored in the UAE, on infrastructure from cloud providers that hold SOC 2 Type 2 and ISO 27001 certifications. Coaching Loft is based in Dubai. Some services we rely on to run the platform, such as email delivery, payments, video meetings and calendar sync, process data outside the UAE; they are covered in our Privacy Policy. For transfers of personal data from the European Union, see our GDPR Compliance document.
Yes. Data is encrypted in transit, with HTTPS enforced and current TLS versions required, and data is encrypted at rest. 256-bit encryption is included on every plan.
Not by default. The permission to open session notes (View session log data) is locked for the whole account, and no one in your account can switch it on, including the account owner. It is unlocked only at the account owner's request to Coaching Loft, and can then be granted role by role. Program Sponsors see the engagements and packages they are assigned to, so they can follow progress without seeing session content.
Yes. Single sign-on connects Coaching Loft to your organization's identity provider and is a paid add-on for firm and enterprise accounts, priced by the number of coach seats. Two-factor authentication uses an authenticator app such as Google Authenticator or Microsoft Authenticator, and enterprise administrators can require it for their coaches and coachees.
Data processing agreements are available for enterprise clients. If you handle protected health information, a Business Associate Agreement is available on request, as described on our HIPAA Compliance page. Contact us to start either one.
Request our security documentation, or book a demo and bring your IT questions.
See also our Privacy Policy, GDPR Compliance, HIPAA Compliance and Terms of Service.