Security
LAST UPDATED: July 31, 2026
OTO.Coach Inc (“OTO”) provides sensor hardware and cloud-based software that assess physiological state and deliver related insights. This page summarizes how we safeguard customer data and systems so external stakeholders can review our security posture without signing in.
Related public documents: Privacy Notice · Terms of Service · Contact
1. Security program
OTO maintains an information security program with approved policies covering access control, cryptography, data management, secure development, operations security, incident response, business continuity and disaster recovery, vendor management, and human resource security. Controls are reviewed on an ongoing basis as part of our compliance program.
2. Infrastructure and hosting
Production application and data services are hosted on Microsoft Azure. We use cloud network controls, logging, and security monitoring (including Microsoft Defender) to help detect and respond to threats against our environment.
3. Data encryption
Sensitive data is protected with encryption in transit (TLS) and encryption at rest. Cryptographic controls and key management practices are defined in our cryptography policy and applied across production systems and storage.
4. Access controls
Access to systems and data is limited to authorized personnel based on job role and least privilege. Our practices include:
- Unique user accounts for personnel access
- Multi-factor authentication for administrative and cloud access where supported
- Periodic access reviews for production and privileged access
- Prompt revocation of access when it is no longer required
5. Application and change security
We follow secure development practices and change management for production changes. Code changes are reviewed before release, and we monitor dependencies and known vulnerabilities as part of ongoing operations.
6. Monitoring and incident response
Critical systems are logged and monitored. OTO maintains a documented incident response plan that defines how we identify, contain, investigate, and remediate security incidents. Where breach notification is required by applicable law, we notify affected parties and authorities as required.
Report a security concern to security@oto.coach or info@oto.coach.
7. Business continuity
We maintain backups and a business continuity / disaster recovery plan intended to restore critical services within defined recovery objectives after an extended outage or disruptive event.
8. Compliance posture
OTO’s current compliance focus includes:
- SOC 2 (Security): security controls designed and operated in accordance with the SOC 2 Trust Services Criteria for Security
- HIPAA: applying HIPAA Security Rule safeguards and Business Associate readiness for applicable healthcare use cases
- GDPR / privacy: privacy practices described in our Privacy Notice, including safeguards for personal data
Our security program is aligned to common control themes used in SOC 2 and related frameworks.
9. Vendors and subprocessors
Third-party vendors that process or access company or customer data are reviewed for security and privacy risk. We use contractual safeguards and ongoing oversight appropriate to the services they provide.
10. Contact
OTO.Coach Inc
5-45B West Wilmot Street
Richmond Hill, ON L4B 2P3
security@oto.coach · info@oto.coach