Security posture

Straight answers on member data - what we store, and who can see it.

No jargon, no overclaiming. This page describes exactly how Coressssfitzaa9 handles member and payment data today, and what we're honestly working on next.

Data at rest

Encrypted storage

Member records, payment history and workout logs sit inside encrypted databases. Backups are encrypted with keys separate from the primary store.

Data in transit

TLS end-to-end

Every request to and from the platform - browser, mobile app or integration - travels over TLS. HTTP redirects to HTTPS at the edge.

Access model

Role-based scopes

Owner, trainer, front-desk and branch roles each see only what their role permits. Trainer roles cannot see fee amounts. Front-desk cannot see full trainer notes.

Payment data

Only what's needed

We record method, amount, cycle and receipt reference. Card numbers, CVV and bank account credentials never touch our servers - they stay with the payment provider.

Retention

Kept while active, exportable always

Member records stay for the lifetime of the membership and up to 24 months after archival - so returning members can be re-activated. Export any time as CSV.

Audit

Every write logged

Every change to a member, payment or plan writes an audit line - who, what, when. Owner accounts can review the trail.

Detail

What sits where, and who can reach it.

Data locationPrimary databases hosted in secure cloud infrastructure. Backups replicated to a secondary region.
Access controlNamed user accounts only. Shared credentials disallowed by design. Password rules enforce length and reuse checks.
RolesOwner, regional lead, branch manager, front desk, trainer, member - each with a defined scope. Custom roles available on multi-branch plans.
Third-party integrationsPayment gateway, SMS provider, email provider - each vetted and scoped to the minimum data needed.
Data exportCSV export for members, payments, attendance and workouts - always available to the owner account.
Deletion requestsOn member request, personal identifiers can be removed while preserving aggregate history for analytics. On account termination, full deletion is available.
Compliance postureWe follow reasonable-industry practices for gym-ops platforms. We do not currently hold external SOC or ISO certifications. This will be added as it becomes relevant - not before.
Incident responseAny incident affecting customer data is disclosed to the affected account within 72 hours of confirmation, along with the scope, impact and remediation.