The questionnaire, already answered
49 questions your security reviewer was going to send us anyway — hosting, encryption, access, retention, certifications and incident response. Most are answered here in full. 6 cover operational detail we give you in a security review under NDA rather than on a public page; they are listed below so you can see nothing has been left out.
Last reviewed September 2026
Company & service
Who you are contracting with and how to reach us.
What legal entity provides the service?
Orafox, Inc. CoReceptionist is the product name; contracts, invoices and data processing agreements are with Orafox, Inc.
Who do we contact about security?
support@coreceptionist.co reaches the team that handles security documentation, questionnaires and vulnerability reports. Mark the subject line accordingly and it is routed directly.
What does the service actually handle?
Visitor registration and check-in, host notification, badge printing, document signing at entry, watchlist and ITAR screening, on-site presence for evacuation, and the resulting visitor logs. It runs on a kiosk tablet, on visitors' own phones by QR code, and in a web dashboard.
Hosting & data residency
Where the platform runs and where your data is stored.
Where is the service hosted?
On Amazon Web Services. We do not operate our own data centres, colocation racks or on-premise infrastructure.
In which region is customer data stored?
A United States AWS region. All customer and visitor data is stored there.
Do you offer EU or UK data residency?
Not today. An EU storage region is under evaluation and prioritised by customer demand. If EU residency is a hard requirement for your organisation, raise it before you invest time in an evaluation — we would rather tell you early than late.
Is the platform multi-tenant, and how is our data separated?
CoReceptionist is a multi-tenant service. Every record — visitors, visitor logs, employees, devices and screening results — carries the owning company's identifier, and every API read and write is scoped server-side to the company bound to the caller's authenticated session. Dashboard users hold a signed, expiring token tied to their company and role; kiosks are paired to a single company at activation and can only submit against that company. There is no cross-tenant read path in the API, and visitor check-in codes are generated per company rather than globally. Multi-site customers can partition further by location, with Location Owner roles scoped to a single site.
Is a self-hosted or on-premise deployment available?
No. CoReceptionist is delivered as a managed cloud service on AWS in the United States only. We do not offer a self-hosted, on-premise or customer-VPC deployment, and it is not on our roadmap — a single managed environment is what lets us patch, monitor and update every customer's kiosks on one schedule.
Encryption
How data is protected in transit and at rest.
Is data encrypted in transit?
Yes. Traffic between visitors, kiosks, the mobile apps, the dashboard and our servers travels over an encrypted TLS connection.
Is data encrypted at rest?
Yes. Visitor records, photos and signed documents are held in encrypted storage on AWS.
How are encryption keys managed?
Data in transit is protected with TLS on every connection — dashboard, kiosk API and integrations. At rest, the database runs on MongoDB Atlas with encryption at rest enabled, and uploaded files (visitor photos, signatures and signed documents) are stored in Amazon S3 with server-side encryption. Key generation, storage and rotation are handled by AWS-managed keys on AWS's own schedule; neither our staff nor our application ever handles raw key material. Application secrets are unique per environment, injected at runtime as configuration, and are never stored in source control. Customer-managed keys (BYOK) are not available today.
Do you store payment card details?
No. Card details are processed by Stripe and never pass through or rest on our systems. We hold a billing contact and a subscription record only.
Access control
Who can sign in, and who inside our company can see your data.
Do you support role-based permissions?
Yes, and they are enforced server-side on every API route against a central permission map rather than in the interface — hiding a button is not access control, so the request itself is rejected at the API. The standard roles are Account Owner (full administrative access, including billing), Location Owner (full access scoped to one site), Receptionist (check-in and check-out, visitor logs, host notification), Employee (pre-register their own guests, see their own visitors), Security (visitor logs, watchlist and ITAR screening results, evacuation reports) and Billing (subscription and invoices only, no visitor data). Roles are scoped by location on multi-site accounts, so a Location Owner cannot see another site's visitor records.
Who at CoReceptionist can access our visitor data?
Access is limited to staff who need it to operate and support the service. Our privacy policy commits that visitor logs and data about your employees and guests are never used for any purpose other than providing and improving the service for you, and we treat that data as your confidential information.
How is a kiosk device authorised, and can it be revoked?
Every kiosk is enrolled with a single-use activation code issued from your dashboard. Any device can be revoked remotely from the dashboard without physical access to the hardware, which is what you want the moment a tablet goes missing.
Visitor data, retention & deletion
What is collected, who controls it, and how long it lives.
What visitor data does the service collect?
Whatever you configure. Typically name and basic contact details, host, visit reason, and check-in and check-out times. You may additionally choose to capture a photo, date of birth, vehicle registration, or documents signed at entry. You decide which fields are collected and you are responsible for ensuring your visitors consent to that collection.
Are you a controller or a processor?
For visitor data you are the controller and we are the processor. You choose what is collected, why, and for how long it is kept. For our own website and billing records we act as controller.
How long is visitor data retained?
For as long as you configure. Retention is set per site, and visitor photos are deleted on your schedule rather than on ours. There is no minimum retention imposed by us.
Can we export our visitor records?
Yes. Visitor logs are exportable from the dashboard as complete, timestamped records — who arrived, who cleared them, what they signed, and when they left.
A visitor has asked us to delete their record. What happens?
You action it directly in your dashboard, because you are the controller of that record. If a visitor contacts us instead, we refer them to the organisation they visited rather than acting on their data ourselves.
Do you sell or share visitor data?
No. We do not sell customer or visitor data, and we do not share it with third parties other than the sub-processors listed on our trust page, who process it solely to deliver the service.
Do you use our data to train AI models?
No. Visitor data is not used to train our own models and is not passed to third-party model providers for training.
Certifications & audits
What we hold today — and what we do not.
Do you have a SOC 2 report?
No. We do not hold a SOC 2 Type I or Type II report today, and there is no report to share under NDA. It is the next compliance investment we intend to make, and we will publish the auditor and observation window when the engagement begins.
Are you ISO 27001 certified?
No. We hold no ISO certification. If your procurement process has a hard certification gate, we will not pass it today.
Do you commission third-party penetration tests?
Not yet. We have not commissioned an independent penetration test, so no report or summary letter exists. Establishing an annual external test sits alongside SOC 2 in the same programme of work.
Are you GDPR compliant?
We publish a GDPR position and handle EU and Swiss resident data under it, and we will sign a data processing agreement on request. Note that all storage is currently in a United States region, which is a material fact for your own transfer assessment.
How do you handle CCPA?
Our privacy policy carries a California Consumer Privacy Act section covering the rights of California residents and how to exercise them.
Will you sign a HIPAA business associate agreement?
No. CoReceptionist is not designed to process protected health information and we do not sign business associate agreements. The platform captures visitor identity and visit context — name, company, host, photo, signature and any custom registration fields you configure — not health records, and customers in regulated environments should not configure custom fields that collect PHI. If your workflow requires handling PHI at the front desk, we would rather say up front that we are not the right fit for that part of it.
Will you sign our data processing agreement?
Yes. A standard pre-signed DPA is in preparation; until it is published we will review and sign yours on request.
Will you complete our security questionnaire?
Yes — SIG Lite, CAIQ or your own internal template. Most standard answers are already on this page, which should shorten the exercise considerably.
Availability & incident response
Uptime, backups, and what happens when something goes wrong.
Do you offer an uptime SLA?
Not on standard subscriptions today. A committed SLA with service credits is on our roadmap for enterprise agreements. The service runs on AWS in the United States and we monitor application health and error rates continuously, with alerting to the engineering team. Kiosk hardware failure, network outages at your own site and scheduled maintenance would sit outside any future commitment.
Is there a public status page?
Not yet. A public status page with incident history is planned. Until it exists, support@coreceptionist.co is the fastest route to a current answer during an incident.
How would we be notified of a data breach?
We will notify affected customers without undue delay on becoming aware of a personal data breach, with what we know, what we are doing, and what you may need to do as controller. Specific contractual notification windows are agreed in your DPA.
How do we report a vulnerability?
Email support@coreceptionist.co with 'security' in the subject line. We will acknowledge receipt and keep you updated through to resolution.
Product security controls
The controls your facilities and compliance teams will ask about.
Can visitors be screened before a badge is issued?
Yes. Visitor details can be checked at check-in against your internal lists and configured databases, including ITAR screening for export-controlled facilities. A matched visitor is held before any badge prints.
What does a flagged visitor see?
A polite request for one more step. The real flag goes to your security team, not to the person standing at the kiosk, and no badge prints until they are cleared.
Can we require escorts for certain visitors?
Yes. Visit types can require an assigned escort, and check-in cannot complete without one.
Can we require NDAs or safety inductions before entry?
Yes. NDAs, site rules and safety inductions are signed on screen and attached to that visit record, and can be enforced per visit reason.
Can we see who is on site during an emergency?
Yes. A live roster shows everyone currently on site — visitors, contractors and couriers — with their hosts and zones, on any device.
Is there an audit trail suitable for inspection?
Visitor logs are complete, timestamped and exportable: who came, who cleared them, what they signed and when they left.
Website & marketing data
What happens on coreceptionist.co itself, separate from the platform.
What cookies and analytics does the website use?
Google Analytics, loaded only after you accept analytics cookies through the consent banner. Declining leaves analytics off rather than merely hiding the banner.
Where do website form submissions go?
Contact and demo form submissions are delivered through Web3Forms and land with our sales and support team. They are used to respond to your enquiry.
Who operates the website chat widget?
Freshworks (Freshchat). Conversations and the contact details you provide in them are processed there.
Still have questions?
Send the ones we have not answered here and we will add them to this page.