Boards, funders, and compliance committees regularly ask how CoolFocus protects the information you keep in it. This article lays out the practices behind the product, so you can hand it to them directly.
CoolFocus is built to serve organizations that handle sensitive personal and health information. The controls below reflect what that responsibility requires.
Annual HIPAA audits conducted with our compliance partner, Van Rein Compliance.
Written policies covering staff responsibilities, security training, and incident response.
A Business Associate Agreement (BAA) that every organization can review, sign, and download for its own records.
See Legal & Compliance Settings.
Within our own company:
Multi-factor authentication is required on every internal system our team uses — cloud infrastructure, source control, email, and administrative tools.
Unique named accounts. We do not use shared logins.
Least-privilege access: staff have the access their role requires, and no more.
Within your organization's data, under your control:
Role-based permissions through user groups.
Record-level restrictions through data access rules, where your plan includes them.
Optional restriction of sign-ins to approved network locations.
Multi-factor authentication that any staff member can turn on, and that an administrator can require for everyone.
See Security Settings at a Glance for each of these.
Data is encrypted in transit and at rest.
Credentials and keys are held in managed secret vaults — never in source code or configuration files.
All code is kept in version control.
Every change is reviewed and approved by another person before it reaches production.
Development, staging, and production run as separate environments.
Automated tests and checks must pass before any deployment.
We keep a durable record of what was deployed, when, and by whom.
Automated dependency scanning, so known vulnerable libraries are flagged as soon as they are published.
Regular patching of operating systems, runtimes, and frameworks.
Centralized application and infrastructure logs with defined retention periods.
An audit trail of administrative actions — both ours and your own administrators'.
Alerting on errors, downtime, and suspicious activity such as repeated failed sign-ins.
A public status page at status.coolfocus.app.
Your administrators can review the security-relevant portion of this themselves — see Security Log and User Logs.
Automated backups on a defined frequency and retention schedule.
Periodic test restores.
A business continuity plan developed with Van Rein Compliance.
Maintaining recoverable backups is also a HIPAA requirement. For the full retention schedule — point-in-time, weekly, monthly, and yearly — and how the audit log is used to reconstruct changed data, see How WayCool Stores and Backs Up Your Data.
A published list of subprocessors — the vendors that may handle customer data while we provide the service.
Annual review of those vendors.
Business Associate Agreements in place with vendors that handle protected health information.
The subprocessor list is linked from Legal & Compliance Settings.
Terms of Service and Privacy Policy, both published and linked from Legal & Compliance settings.
A process for notifying customers of significant changes affecting their data.
A security contact for reporting a concern or a vulnerability.
Security questionnaires, custom BAAs, Data Processing Agreements, questions about certifications and audit documentation, and deeper review packets are all things we handle directly. Email [email protected] or open a conversation in Help — these requests are routed to our legal and security team rather than general support, and you will get a substantive answer rather than a form response.