Trust

Your data.
Locked down.

Encryption, access controls, audits. Boring, critical, done right.

TLS 1.3
In transit
AES-256
At rest
Daily · 30d
Backups
Type II
SOC 2
What we do
The essentials,
well.

Encryption

TLS 1.3 in transit. AES-256 at rest. Secrets in AWS KMS. Full-disk encryption on every production volume.

Access controls

SSO + 2FA required for all staff. Principle of least privilege. Engineer access is logged and reviewed quarterly.

Backups

Daily encrypted backups. 30-day retention. Restore drills run monthly. Cross-region replication for disaster recovery.

Monitoring

24/7 anomaly detection on auth events, payments, and data access. Automated alerting to on-call.

Audits

SOC 2 Type II audited annually. Penetration tests twice a year by a third-party firm. Report available on request.

Infrastructure

AWS us-east-1. Private VPC. No production data ever touches developer laptops. CI/CD with signed deploys.

Compliance
Where we stand.

Certifications and frameworks we align with. We publish honestly — if we don't have it, we'll say so.

FrameworkStatusNotes
SOC 2 Type II✓ CertifiedAnnual audit · renewed Jan 2026
GDPR✓ CompliantDPA available · EU sub-processor list published
CCPA / CPRA✓ CompliantCalifornia resident rights supported
PCI DSS✓ Via StripeHandled end-to-end by Stripe — we never touch card data
HIPAANot certifiedDon't store medical records on Z6.
ISO 27001In progressTarget: Q4 2026
Responsible disclosure
Found a vulnerability?

Please email info@z6coaching.com with details. We'll acknowledge within 24 hours and patch critical issues within 7 days.

Rules: don't access data that isn't yours, don't disrupt the service, don't publish until we've patched.

We don't run a formal bug bounty program yet — but we send thank-you swag, a public credit on this page (if you want it), and a real conversation with engineering. We're working on something more formal.

PGP key
3A7F 9B2C 8E4D 1A6F · z6coaching.com/pgp.asc
Hall of fame

Thanks to

@samira.r

Rate-limit bypass

Feb 2026 · High

@dnguyen

IDOR on exports

Jan 2026 · Medium

@blacksage

CSRF in webhook settings

Nov 2025 · Medium

@jamelindo

XSS in rich-text editor

Sep 2025 · High

All systems operational
99.98% UPTIME TRAILING 90 DAYS
Report an issue →