Security
McCoy Terminal is the enterprise operating system that powers curriculum creation, management, deployment, certification, analytics, and learning distribution across the McCoy ecosystem. Organizations can create once and deploy everywhere through Surface, the McCoy App, their own applications, websites, portals, or custom integrations via API.
This document provides an overview of the security, privacy, infrastructure, compliance, operational, and AI governance principles that guide the design and operation of McCoy Terminal.
Enterprise Security Summary
Built on Google Cloud Platform (GCP)
Defense-in-depth security architecture
Encryption in transit and at rest
Role-based access controls and tenant isolation
Enterprise SSO support and identity integration options
Comprehensive logging and auditability
API security controls and credential management
Business continuity and disaster recovery procedures
Privacy-first and minimal-data deployment options
SOC 2-aligned security program in development
AI governance and customer data protection policies
Security Principles
McCoy Terminal is built around five foundational principles:
Data Minimization by Default
We collect, process, and retain only the information necessary to operate the platform and deliver agreed functionality.
Customer Control and Tenant Isolation
Organizations maintain ownership and control over users, permissions, identities, and configurations.
Defense in Depth
Multiple layers of controls protect infrastructure, applications, data, and operations.
Transparency and Auditability
Administrative actions, access events, and critical system activity are logged and reviewable.
Continuous Improvement
Security is continuously evaluated and improved as the platform evolves.
Platform Coverage Across the McCoy Ecosystem
The security controls described in this document apply to McCoy Terminal and extend to the broader McCoy ecosystem, including:
Surface
McCoy App
Verify
Terminal API
Enterprise deployments and white-label implementations
Security standards are applied consistently across products and services.
Cloud & Infrastructure Security
McCoy Terminal operates on Google Cloud Platform (GCP), leveraging enterprise-grade infrastructure and managed services.
Controls include:
Network segmentation and firewall protections
Controlled ingress and egress pathways
DDoS-aware architecture patterns
Identity and access management controls
Hardened infrastructure configurations
Monitoring and alerting systems
Backup and disaster recovery capabilities
Infrastructure resiliency and redundancy
Privacy-First Data Architecture
Many organizations prefer to minimize personal data collection whenever possible.
McCoy Terminal supports:
Organization-managed identifiers
Pseudonymous accounts
Configurable user profile fields
Aggregated analytics
De-identified reporting options
McCoy does not:
Sell personal data
Use customer data for advertising
Train AI models on customer content without explicit agreement
Collect unnecessary personal information
Data Encryption & Protection
Data protection controls include:
TLS encryption for data in transit
Encryption at rest for stored information
Secure key management practices
Secrets management and credential rotation
Restricted administrative access
Continuous monitoring of critical systems
Tenant Isolation & Access Controls
McCoy Terminal supports enterprise multi-tenant deployments through:
Logical tenant separation
Role-based access controls (RBAC)
Least-privilege access management
Administrative activity logging
Permission governance controls
Authentication, Identity & SSO
Identity security capabilities include:
Enterprise SSO support
Centralized authentication management
Secure login workflows
Session security controls
User provisioning options
Identity governance integration capabilities
Logging, Monitoring & Audit Trails
McCoy Terminal maintains logs that support:
Availability monitoring
Performance monitoring
Security monitoring
Administrative audits
Configuration tracking
Incident investigations
Logging practices are designed to balance operational visibility with privacy and data minimization objectives.
Secure Development & Change Management
Security is integrated throughout the software lifecycle.
Practices include:
Secure coding standards
Peer-reviewed code changes
Dependency and vulnerability management
Development and production environment separation
Deployment traceability
Ongoing security reviews
Incident Response & Vulnerability Management
McCoy maintains procedures designed to:
Detect security incidents
Investigate and contain threats
Remediate vulnerabilities
Notify customers when appropriate
Conduct post-incident reviews
Improve future controls
Business Continuity & Disaster Recovery
McCoy maintains operational procedures intended to support platform resilience.
Capabilities include:
Versioned backups
Recovery procedures
Infrastructure redundancy
Availability monitoring
Business continuity planning
Recovery objectives are reviewed and improved as the platform scales.
Data Retention, Export & Deletion
McCoy Terminal supports enterprise data lifecycle requirements through:
Defined retention practices
Data export capabilities
Customer-requested deletion procedures
Controlled offboarding workflows
Contractual and legal compliance requirements
API & Integration Security
The McCoy Terminal API includes:
Authenticated access requirements
Scoped credentials and permissions
Revocable access tokens
Rate limiting protections
Usage logging and monitoring
Enterprise-friendly access controls
API access is designed to be secure, measurable, and manageable at scale.
AI & Customer Data Usage Policy
Artificial intelligence is a core component of the McCoy platform. Customer trust remains fundamental to our approach.
McCoy does not:
Train foundation models on customer content without explicit agreement
Share customer data with third parties for model training without authorization
Use customer content outside the agreed scope of services
Organizations retain ownership of their content and data.
Where AI services are used to generate, review, organize, or enhance curriculum content, those services operate within controlled workflows designed to protect customer information.
Security & Compliance Program
McCoy is building a security and compliance program aligned with widely recognized enterprise security standards and best practices.
Areas of focus include:
Access controls
Change management
Incident response
Logging and monitoring
Risk management
Vendor management
Business continuity
Disaster recovery
Security documentation can be provided to support enterprise procurement and review processes.
Subprocessors & Third-Party Services
McCoy maintains an inventory of key infrastructure, technology, and service providers involved in delivering the platform.
Relevant information can be provided during customer security reviews and procurement processes.
Enterprise Security Reviews
McCoy supports customer security and procurement reviews through documentation such as:
Security questionnaires
Architecture summaries
Data flow overviews
Compliance materials
Vendor documentation
Privacy and security policies
We work collaboratively with organizations to meet security, governance, and operational requirements.
Our Commitment
Security, privacy, and trust are foundational to McCoy Terminal.
Our objective is to provide organizations with the ability to create once and deploy everywhere while maintaining strong security controls, responsible data practices, operational transparency, and enterprise-grade governance across the entire McCoy ecosystem.
Contact us for further security support
If your organization requires heightened security protocols, custom controls, or restricted deployment environments (e.g., defense or government use cases), please contact us to coordinate a tailored security review.