Third Party Index

Snapshot 21840

Document
Security page
URL
https://www.coffeepals.com/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
59168 bytes
SHA-256 (raw)
d3ee01c1817df205fd6cb8a4231ef5868e1d4c0fe010f0c2d2d118fba3d76d3b
SHA-256 (normalized text)
4d3af21e4c9bf6356c6f26194e1530fb1e1a7cc222af444d5db582049f9ee43f

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Security
Enterprise-grade security,
built in from day one.
CoffeePals is SOC 2 Type 2 audited and Microsoft 365 certified. We partner exclusively with cloud providers meeting SOC 2, ISO 27001, and PCI-DSS standards — so your data is protected at every layer.
How we protect your data
Security isn't an afterthought — it's embedded in every layer of our platform.
Data Encryption
All data is encrypted in transit with TLS 1.3+ and at rest with AES-256. Stored across multiple AWS regions in the United States.
Limited Data Access
CoffeePals only receives messages sent directly to the bot. We have zero access to private messages, group chats, or channel conversations.
Cloud Infrastructure
Hosted on AWS through providers certified for SOC 2, ISO 27001, and PCI-DSS. Physical security managed by AWS across multiple data centers.
Access Control
Least-privilege access for every team member. Deny-by-default policy. Multi-factor authentication required across all internal services.
Secure Development
Every feature undergoes code review, automated testing, and OWASP Top 10 review. Production releases require pull request approval from senior staff.
Incident Response
Security issues are our top priority. In compliance with GDPR, affected customers are notified within 72 hours of any incident detection.
Vendor Management
Every vendor is assessed against our formal risk evaluation policy before being granted access to any customer data. See our current subprocessors; customers are notified whenever one is added or removed.
SSO & Authentication
Passwordless authentication by default. Enterprise SSO available via Azure AD. Login tokens expire after one hour.
Need more detail?
We're happy to share our security policies and documentation under NDA. Talk to our team.
Contact Sales
For vulnerability disclosures, email [email protected]