Skip to content
CoachOS
Security and data

You are trusting us with student and parent records

CoachOS uses institute-level data separation, role-based permissions and audit records. Review these controls with us and discuss your requirements before onboarding.

Security controls

Protect your institute's records and access

Explore how access controls, audit records and data export support your team.

Separated by institute at the row level

Records are scoped to each institute. Access controls restrict staff to their own institute's fees, tests, materials, enquiries and audit records.

Protected sign-in sessions

Access and refresh tokens live in HttpOnly, Secure, SameSite cookies. No token is kept in browser storage. Refresh tokens rotate on every use, and replaying an old one revokes the whole session family.

Role and branch aware permissions

Owners, branch admins, faculty, students and parents have role-specific access. Branch admins are scoped to the branch they manage.

An audit trail you can actually read

A tenant scoped audit log with module and search filters, recording real actions and real actors. Bulk imports and sensitive operations write records too.

Credentials never reach the browser

Payment gateway keys are masked server side. Incomplete live payment configuration is rejected rather than half applied, and webhook signatures are verified.

Your data stays exportable

Institute admins can export their own roster, parent, faculty and fee data as CSV through authorised endpoints. Leaving should never require asking us for a favour.

Before onboarding

Discuss your security requirements

Confirm hosting, service terms and any certification requirements with the CoachOS team before bringing real records into the product.

  • Confirm hosting location and data-processing terms for your institute.
  • Review access permissions for owners, branch admins and staff.
  • Agree support arrangements and service terms in writing.
  • Discuss any independent security assessment or certification requirements.

We will discuss these requirements with you during the demo and confirm the agreed scope before onboarding.

Your data

It stays yours, and you can take it with you

  • Institute admins can export the roster, parent, faculty and fee data as CSV from inside the product, without asking us.
  • Enquiries submitted through your public website are sanitised on the server before anything is stored.
  • Payment gateway credentials are masked before they leave the server and never reach a browser.
  • Every institute's rows are scoped separately, and attempts to read another institute's records by direct link return nothing.
  • We use your details only to run your institute's account and to support you. We do not sell or share them.
Book a demo

Bring your technical person to the call

Review permissions, institute data separation and data export in a live walkthrough with the CoachOS team.

Prefer to look around first? Read the questions other owners ask.

Book a 30 min demo