Security

What happens to your clients' data.

You are asking your clients to trust a phone call that carries your name. That only holds up if what sits behind it is handled properly.

This page is the plain version, including the parts that do not flatter us. If anything here turns out to be out of date, treat it as a bug and tell us.

Where your data lives

Our server is in Sydney, Australia. It is a private server we run ourselves, not shared hosting, and your account data sits on it.

That is only half an answer, so here is the other half. Placing a phone call, sending a text, turning a call into a summary and emailing you all need outside providers, and most of those providers are in the United States. Your clients' details pass through them to get that work done. They are listed further down rather than left for you to guess at.

What is encrypted

Everything personal your account holds is encrypted where it is stored:

  • Your clients' names, phone numbers and email addresses
  • The transcript of every call
  • Recordings and documents you upload, including the recordings you made of your own voice
  • Your own details, including your address and payout details

The method is AES-256-GCM, applied field by field in the database and file by file on disk.

The part that matters more than the algorithm: the keys are not kept on that server. Each key is split in two, and one half lives on a machine somewhere else entirely. The server rebuilds them in memory when it starts, and never writes them down. We tested that by restarting the server with no copy of the keys on it at all, and watching it come back on its own.

So a copy of our server's disk is ciphertext with nothing on it that opens it.

Who else touches it

Running the calls means handing parts of your clients' data to other companies. This is all of them.

ProviderWhat it doesWhat it receives
Voice providerPlaces the check-in callThe client's phone number, the call audio, the transcript
Telnyx, TwilioSends and receives texts, carries the callsThe client's mobile number and the message
AnthropicTurns a call into your summary, flags anything urgentThe text of the transcript
PostmarkSends emailEmail addresses and message content
ZoomOnly if you connect it: brings in session recordingsThe recordings you choose to pull in
StripeYour billingYour card and company details, never client data

Recordings of your check-in calls stay with the voice provider. We hold the transcript and a playback link, not the audio file.

When you upload a recording yourself, to build a client or a program from a session, that one is transcribed on our own machine and the audio is not sent anywhere.

There is no third-party analytics or tracking inside the app. No Google Analytics, no session recording, no advertising pixels once you are signed in. Our error monitoring is our own and stays on our server.

Getting into your account

  • Passwords are stored as scrypt hashes. Nobody can read yours back, us included.
  • A sign-in link works once, expires in fifteen minutes, and only a hash of it is stored, so reading our database gets an attacker nothing usable.
  • Two-factor authentication is available on every account, and required on new ones. It is a code from an authenticator app on your phone, backed by recovery codes for the day you lose the phone.
  • One coach can never see another coach's clients. That separation is enforced on the server on every request, not in the browser where it could be bypassed.

What we do not have

You should hear this part from us rather than find it out later.

  • No external audit or penetration test. The security checks we run are our own. No independent firm has tried to break in and written it up.
  • No SOC 2, ISO 27001 or HIPAA certification. We hold none of them. ShoUp is not built for regulated health records, and you should not use it as though it were.
  • No uptime promise. Our terms say so plainly, and we would rather you planned around that than were surprised by it.
  • Not everything stays in Australia. The providers above are mostly US-based, and our encrypted database backup is stored offshore as ciphertext that only we can open.
  • Encryption does not protect you from us. We can read your data when we are supporting you. What it protects against is a stolen disk or a stolen backup, which is a real risk and a different one.

Your data is yours

You can download a complete copy of your account any time from Settings: your clients, your programs, the transcript of every call and your billing history. You do not have to ask us, and you do not have to be leaving.

We do not sell personal information, and one coach's client information is never shown to another coach. The full detail is in our privacy policy and terms.

Found a problem?

If you think you have found a security issue, email privacy@shoup.ai and say what you found and how to reproduce it. We will confirm we have it, and we will not come after anyone who reports something in good faith and does not go digging through other people's data to prove it.

Last reviewed 11 August 2026

Questions we have not answered here?

Ask before you sign up, not after. If the answer is unflattering you will get it anyway.

Request access