New14 days free, no card.Start →

Your data is yours. We take that seriously.

We don't have SOC 2 (yet). But we'll describe exactly what we do – so you can decide for yourself.

Encryption

TLS 1.3 in transit, AES-256 at rest. Passwords hashed via bcrypt through Supabase Auth.

Data isolation

Postgres Row-Level Security. Every query is bound to a user – nothing leaks by accident.

EU data residency

Supabase EU region (Frankfurt). Cloudflare R2 EU jurisdiction. No transfer outside the EEA.

Authentication

Magic link or email/password. JWTs with short expiry, rotating refresh tokens.

Backups

Daily automated backups with 30-day retention. Point-in-time recovery at the Supabase level.

Audit logs

Key actions (login, password change, client deletion) are logged with timestamp and IP.

What we don't promise

We'd rather describe where we stand than play buzzword bingo.

We don't have SOC 2 or ISO 27001. For a team our size that would mean more paperwork than real change – and the real change we already have.

If you need formal certification for corporate compliance, let us know. It's a valid request and we're actively watching the ecosystem.

Report a vulnerability: bezpecnost@pocketcoach.cz

Want to know more?

We'll send a security brief on request.

Security – PocketCoach | PocketCoach