Security

Black and white photo taken through a powerful lens showing a part of a vehicle's grille and a tire.

McCoy Terminal is the enterprise operating system that powers curriculum creation, management, deployment, certification, analytics, and learning distribution across the McCoy ecosystem. Organizations can create once and deploy everywhere through Surface, the McCoy App, their own applications, websites, portals, or custom integrations via API.

This document provides an overview of the security, privacy, infrastructure, compliance, operational, and AI governance principles that guide the design and operation of McCoy Terminal.

Enterprise Security Summary

  • Built on Google Cloud Platform (GCP)

  • Defense-in-depth security architecture

  • Encryption in transit and at rest

  • Role-based access controls and tenant isolation

  • Enterprise SSO support and identity integration options

  • Comprehensive logging and auditability

  • API security controls and credential management

  • Business continuity and disaster recovery procedures

  • Privacy-first and minimal-data deployment options

  • SOC 2-aligned security program in development

  • AI governance and customer data protection policies

Security Principles

McCoy Terminal is built around five foundational principles:

Data Minimization by Default

We collect, process, and retain only the information necessary to operate the platform and deliver agreed functionality.

Customer Control and Tenant Isolation

Organizations maintain ownership and control over users, permissions, identities, and configurations.

Defense in Depth

Multiple layers of controls protect infrastructure, applications, data, and operations.

Transparency and Auditability

Administrative actions, access events, and critical system activity are logged and reviewable.

Continuous Improvement

Security is continuously evaluated and improved as the platform evolves.

Platform Coverage Across the McCoy Ecosystem

The security controls described in this document apply to McCoy Terminal and extend to the broader McCoy ecosystem, including:

  • Surface

  • McCoy App

  • Verify

  • Terminal API

  • Enterprise deployments and white-label implementations

Security standards are applied consistently across products and services.

Cloud & Infrastructure Security

McCoy Terminal operates on Google Cloud Platform (GCP), leveraging enterprise-grade infrastructure and managed services.

Controls include:

  • Network segmentation and firewall protections

  • Controlled ingress and egress pathways

  • DDoS-aware architecture patterns

  • Identity and access management controls

  • Hardened infrastructure configurations

  • Monitoring and alerting systems

  • Backup and disaster recovery capabilities

  • Infrastructure resiliency and redundancy

Privacy-First Data Architecture

Many organizations prefer to minimize personal data collection whenever possible.

McCoy Terminal supports:

  • Organization-managed identifiers

  • Pseudonymous accounts

  • Configurable user profile fields

  • Aggregated analytics

  • De-identified reporting options

McCoy does not:

  • Sell personal data

  • Use customer data for advertising

  • Train AI models on customer content without explicit agreement

  • Collect unnecessary personal information

Data Encryption & Protection

Data protection controls include:

  • TLS encryption for data in transit

  • Encryption at rest for stored information

  • Secure key management practices

  • Secrets management and credential rotation

  • Restricted administrative access

  • Continuous monitoring of critical systems

Tenant Isolation & Access Controls

McCoy Terminal supports enterprise multi-tenant deployments through:

  • Logical tenant separation

  • Role-based access controls (RBAC)

  • Least-privilege access management

  • Administrative activity logging

  • Permission governance controls

Authentication, Identity & SSO

Identity security capabilities include:

  • Enterprise SSO support

  • Centralized authentication management

  • Secure login workflows

  • Session security controls

  • User provisioning options

  • Identity governance integration capabilities

Logging, Monitoring & Audit Trails

McCoy Terminal maintains logs that support:

  • Availability monitoring

  • Performance monitoring

  • Security monitoring

  • Administrative audits

  • Configuration tracking

  • Incident investigations

Logging practices are designed to balance operational visibility with privacy and data minimization objectives.

Secure Development & Change Management

Security is integrated throughout the software lifecycle.

Practices include:

  • Secure coding standards

  • Peer-reviewed code changes

  • Dependency and vulnerability management

  • Development and production environment separation

  • Deployment traceability

  • Ongoing security reviews

Incident Response & Vulnerability Management

McCoy maintains procedures designed to:

  • Detect security incidents

  • Investigate and contain threats

  • Remediate vulnerabilities

  • Notify customers when appropriate

  • Conduct post-incident reviews

  • Improve future controls

Business Continuity & Disaster Recovery

McCoy maintains operational procedures intended to support platform resilience.

Capabilities include:

  • Versioned backups

  • Recovery procedures

  • Infrastructure redundancy

  • Availability monitoring

  • Business continuity planning

Recovery objectives are reviewed and improved as the platform scales.

Data Retention, Export & Deletion

McCoy Terminal supports enterprise data lifecycle requirements through:

  • Defined retention practices

  • Data export capabilities

  • Customer-requested deletion procedures

  • Controlled offboarding workflows

  • Contractual and legal compliance requirements

API & Integration Security

The McCoy Terminal API includes:

  • Authenticated access requirements

  • Scoped credentials and permissions

  • Revocable access tokens

  • Rate limiting protections

  • Usage logging and monitoring

  • Enterprise-friendly access controls

API access is designed to be secure, measurable, and manageable at scale.

AI & Customer Data Usage Policy

Artificial intelligence is a core component of the McCoy platform. Customer trust remains fundamental to our approach.

McCoy does not:

  • Train foundation models on customer content without explicit agreement

  • Share customer data with third parties for model training without authorization

  • Use customer content outside the agreed scope of services

Organizations retain ownership of their content and data.

Where AI services are used to generate, review, organize, or enhance curriculum content, those services operate within controlled workflows designed to protect customer information.

Security & Compliance Program

McCoy is building a security and compliance program aligned with widely recognized enterprise security standards and best practices.

Areas of focus include:

  • Access controls

  • Change management

  • Incident response

  • Logging and monitoring

  • Risk management

  • Vendor management

  • Business continuity

  • Disaster recovery

Security documentation can be provided to support enterprise procurement and review processes.

Subprocessors & Third-Party Services

McCoy maintains an inventory of key infrastructure, technology, and service providers involved in delivering the platform.

Relevant information can be provided during customer security reviews and procurement processes.

Enterprise Security Reviews

McCoy supports customer security and procurement reviews through documentation such as:

  • Security questionnaires

  • Architecture summaries

  • Data flow overviews

  • Compliance materials

  • Vendor documentation

  • Privacy and security policies

We work collaboratively with organizations to meet security, governance, and operational requirements.

Our Commitment

Security, privacy, and trust are foundational to McCoy Terminal.

Our objective is to provide organizations with the ability to create once and deploy everywhere while maintaining strong security controls, responsible data practices, operational transparency, and enterprise-grade governance across the entire McCoy ecosystem.

Contact us for further security support

If your organization requires heightened security protocols, custom controls, or restricted deployment environments (e.g., defense or government use cases), please contact us to coordinate a tailored security review.