Kool Security

Security

Security isn't a feature we added. It is how Kool is built, from passwordless sign-in to an encrypted edge network.

How we protect you

The six pillars behind every conversation, story and call on Kool. Follow the line.

Passwordless auth

Sign-in is a one-time email code stored hash-only, so there is no password to phish or leak. Optional authenticator 2FA and per-device session revocation.

Encryption everywhere

TLS for everything in transit, encryption at rest on Cloudflare D1 and R2, and encrypted WebRTC media for calls and live.

Edge-native infrastructure

Kool runs entirely on Cloudflare, with WAF, DDoS protection and rate limiting in front of all traffic by default.

Row-level tenancy

Every record is isolated per owner at the database layer; staff access is least-privilege and 2FA-gated.

No trackers, no data sales

No third-party analytics, no advertising SDKs, no data brokers. What happens in Kool stays in Kool.

Monitored 24/7

Automated probes watch every service around the clock, open incidents automatically and publish them live on our status page.

Our practices

Data protection

GDPR and CCPA aligned, with a signable DPA, EU Standard Contractual Clauses and a 72-hour breach notification commitment. See the Trust Center for the full picture.

Least data, least access

We collect only what the product needs to work, keep it only as long as needed, and limit who and what can touch it.

Vetted subprocessors

A deliberately short list of infrastructure providers, published openly at /subprocessors with 30 days' change notice for business customers.

Continuous review

Dependencies, permissions and configurations are reviewed continuously; SOC 2 and ISO 27001 readiness are on our roadmap.

Found a vulnerability?

We work with good-faith security researchers and respond fast. Tell us what you found, including steps to reproduce, and we'll take it from there.