Security

Your Sales Data Stays Private.
Zero Exceptions.

FireCoach is built with enterprise-grade security to protect your sales methodology, pitch decks, and customer data. Your competitive advantage is never shared, sold, or exposed.

SOC 2

Compliant

Audited for security, availability, and confidentiality controls.

GDPR

Ready

Full compliance with EU data protection regulations.

AES-256

Encryption at Rest

All stored data encrypted with AES-256 industry standard.

Zero

Data Selling

Your data is never sold, shared, or used to train public models.

Security Built Into
Every Layer.

01

End-to-End Encryption

All data transmitted between your browser and our servers uses TLS 1.3 — the current gold standard for transport security. No data travels in plaintext, ever.

02

AES-256 at Rest

Every piece of stored data — your roleplay sessions, scorecards, pitch decks, and account information — is encrypted using AES-256. The same standard used by banks and defense agencies.

03

Role-Based Access

Granular permissions by role: rep, manager, and admin. Your data is segmented and scoped so people can only access what they need. Managers see their team; admins control the organization.

04

SSO & SAML

Connect your existing identity provider. We support Okta, Azure AD, and Google Workspace via SAML 2.0. Enforce your organization’s authentication policies without managing another set of credentials.

05

Regular Audits

We conduct quarterly third-party penetration testing to identify and remediate vulnerabilities before they become risks. Security is not a one-time checklist — it’s an ongoing operational discipline.

06

Zero Data Selling

Your sales methodology, call recordings, and pitch decks are never sold to third parties, used to train AI models for other customers, or shared outside your organization. Full stop.

Your Competitive Advantage

Your Sales Methodology is Protected.

We do not use your scenarios, scorecards, pitch decks, or call recordings to train AI models for other companies. Ever.

Your competitive intelligence stays exclusive to your organization. The way your best reps handle objections, the specific discovery questions that work for your product, the language that closes deals in your market — none of that leaves your account, and none of it trains the AI that your competitors use.

We process your data for you. That’s the only purpose it serves.

Common Questions

Where is our data hosted?

FireCoach runs on Cloudflare’s global infrastructure with data centers in the United States. Enterprise customers can request data residency options for EU compliance. All infrastructure providers are SOC 2 certified.

Who at FireCoach can access our data?

Access to customer data is strictly limited to personnel who require it to provide the service or resolve a support issue, and only with explicit authorization. Access is logged, audited, and reviewed quarterly. We follow the principle of least privilege — no one has broader access than their role requires.

Can we delete our data?

Yes. You can request deletion of your account data at any time by contacting privacy@firecoach.ai. Upon verified request, your data will be permanently deleted within 30 days. Payment records are retained for 7 years as required by financial regulations.

Do you offer a Data Processing Agreement (DPA)?

Yes. A DPA is available for customers who require one for GDPR or other regulatory compliance. Contact security@firecoach.ai to request a copy and discuss any organization-specific requirements.

What is your incident response policy?

In the event of a security incident affecting customer data, we will notify affected customers within 72 hours of discovery, consistent with GDPR requirements. Our incident response team is on-call 24/7. We will provide timely updates throughout the investigation and a full post-incident report once resolved.

Have security
questions?

security@firecoach.ai → Book a Demo