Your visitors' data, accounted for
Where your data lives, who can touch it, how long we keep it, and which credentials we do and don't hold. Written for the person who has to sign off on us.
Last reviewed September 2026
What is true right now
The platform runs on AWS. We do not operate our own data centres or colocation hardware.
Customer and visitor data is stored in a US AWS region. We do not currently offer an EU or UK storage region — if that is a requirement for your organisation, tell us before you evaluate us.
Traffic between visitors, kiosks, the dashboard and our servers travels over an encrypted TLS connection. This has been our stated practice since our first published privacy policy.
Visitor records, photos and signed documents are held in encrypted storage on AWS.
Card details are processed by Stripe. We do not process, store or take custody of card numbers at any point.
Retention periods are configured per site, and visitor photos are deleted on your schedule rather than ours. Records can be exported before deletion.
Every kiosk is enrolled with a single-use code issued from your dashboard, and any device can be revoked remotely without touching the hardware.
Visitor logs and data about your employees and guests are used only to provide and improve the service for you. We do not sell them, and we do not use them to train AI models.
Everyone who touches your data
The complete list of third parties that process customer or visitor data on our behalf. We will give you 30 days' notice before adding a new one — email support@coreceptionist.co to be added to that notification list.
| Sub-processor | Purpose | Data processed | Region |
|---|---|---|---|
| Amazon Web Services | Application hosting and data storage | All customer and visitor data | United States |
| Stripe | Subscription billing and payment processing | Billing contact and payment details | United States |
| Freshworks (Freshchat) | Website chat and customer support | Support conversations and contact details you provide | United States |
| Google Analytics | Website analytics on coreceptionist.co | Website usage data, subject to cookie consent | United States |
| Web3Forms | Contact and demo form delivery on the website | Name, email, company and message you submit on our forms | United States |
| Amazon SES | Host notifications, visitor invitations and transactional email | Host and visitor names, email addresses, visit details | United States |
| Twilio | Host notification by text message | Host phone numbers and notification content | United States |
What we are working toward
Dated commitments, not aspirations. Nothing below is claimed as complete anywhere else on this site.
SOC 2 Type II
We do not hold a SOC 2 report today. It is the credential most of our enterprise prospects ask for first, and it is the next compliance investment we intend to make. We will publish the auditor and the observation window when the engagement starts, rather than announcing an intention with no date behind it.
Independent penetration test
We have not yet commissioned a third-party penetration test, so there is no report to share and we make no claim otherwise. Establishing an annual external test, with a summary letter available under NDA, sits alongside SOC 2 in the same programme of work.
EU data residency
All data is currently stored in a US AWS region. An EU storage region is under evaluation and will be driven by customer demand — if you need it, that demand is how it gets prioritised.
Standard Data Processing Agreement
A pre-signed DPA that you can review without a legal round-trip is in preparation. Until it is published, we will sign a DPA on request.
Refreshed privacy policy and terms
Our published privacy policy and terms predate the current platform and are being rewritten to describe the service as it exists today, including retention, sub-processors and data subject rights.
What you can ask us for
Security Overview
A written summary of our architecture, hosting, access controls and data handling, suitable for attaching to a vendor review.
Data Processing Agreement
Signed on request while the standard pre-signed version is being finalised.
Completed security questionnaire
We will complete your own questionnaire — SIG Lite, CAIQ or an internal template. Most of the standard answers are already published in our security FAQ.
SOC 2 report
No report exists yet. We would rather tell you that plainly than let a badge imply otherwise.
Bring your compliance team
We would rather answer the hard questions early than discover them at contract stage.