Koolay

Security at Koolay

Last updated 2026-04-17

Koolay hosts sensitive nonprofit data โ€” donor records, payment history, member PII, scholarship applications, user accounts. This page summarizes how we protect it.

Certifications and compliance

SOC 2 Type II๐ŸŸก Readiness phase โ€” target report Q3 2026
GDPRโœ… DPA on file, EU SCCs executed, self-service data export and deletion
CCPA / CPRAโœ… Honored; Koolay does not sell personal information
PCI DSSโœ… All card data handled by Stripe (PCI Level 1); we never see card numbers
HIPAAโšช Not required โ€” we do not process health data

Subprocessor certifications we rely on: Supabase SOC 2 Type II, Vercel SOC 2 Type II, Stripe PCI DSS Level 1 / SOC 1/2, AWS SOC 1/2/3 and ISO 27001.

Infrastructure

Access control

Data handling

Secure development

Incident response

Status page

Real-time uptime and incident history: https://koolay.com/status
Target availability: 99.5% monthly.

Internal policies

Available on request under NDA. We maintain 11 internal policies:

  1. Information Security Policy
  2. Access Control
  3. Data Classification
  4. Incident Response
  5. Business Continuity & DR (RTO 4h / RPO 1h)
  6. Vendor Management
  7. Data Retention & Deletion
  8. Security Awareness Training
  9. Backup & Recovery
  10. Change Management
  11. Auth Hardening runbook