How we protect you
The six pillars behind every conversation, story and call on Kool. Follow the line.
Passwordless auth
Sign-in is a one-time email code stored hash-only, so there is no password to phish or leak. Optional authenticator 2FA and per-device session revocation.
Encryption everywhere
TLS for everything in transit, encryption at rest on Cloudflare D1 and R2, and encrypted WebRTC media for calls and live.
Edge-native infrastructure
Kool runs entirely on Cloudflare, with WAF, DDoS protection and rate limiting in front of all traffic by default.
Row-level tenancy
Every record is isolated per owner at the database layer; staff access is least-privilege and 2FA-gated.
No trackers, no data sales
No third-party analytics, no advertising SDKs, no data brokers. What happens in Kool stays in Kool.
Monitored 24/7
Automated probes watch every service around the clock, open incidents automatically and publish them live on our status page.
Our practices
Data protection
GDPR and CCPA aligned, with a signable DPA, EU Standard Contractual Clauses and a 72-hour breach notification commitment. See the Trust Center for the full picture.
Least data, least access
We collect only what the product needs to work, keep it only as long as needed, and limit who and what can touch it.
Vetted subprocessors
A deliberately short list of infrastructure providers, published openly at /subprocessors with 30 days' change notice for business customers.
Continuous review
Dependencies, permissions and configurations are reviewed continuously; SOC 2 and ISO 27001 readiness are on our roadmap.
Found a vulnerability?
We work with good-faith security researchers and respond fast. Tell us what you found, including steps to reproduce, and we'll take it from there.