Last Updated: February 2026 | Version: 2.3.0
✓ Implemented
✓ Implemented
| Layer | Standard | Details |
|---|---|---|
| In Transit | TLS 1.3 | HTTPS enforced, HSTS enabled |
| At Rest | AES-256 | Database encryption, Azure Key Vault |
| Secrets | Azure Key Vault | API keys, tokens, certificates |
| Component | Provider | Certifications |
|---|---|---|
| Compute | Railway | SOC 2 Type II |
| Database | PostgreSQL (Railway) | SOC 2 Type II |
| Cache | Redis (Railway) | SOC 2 Type II |
| Backup | Azure (DR) | ISO 27001, SOC 2 |
| Standard | Status | Timeline |
|---|---|---|
| GDPR (EU) | ✓ Compliant | Active |
| CCPA (California) | ✓ Compliant | Active |
| SOC 2 Type II | In Progress | Q3 2026 |
| ISO 27001 | Planned | Q4 2026 |
We follow a 90-day coordinated disclosure policy.
Report vulnerabilities: security@lifecoach-121.com
We commit to acknowledging reports within 48 hours and providing status updates every 7 days.