← Back to FitnessTrainerOS

Security

Security

Security for FitnessTrainerOS is not a compliance checkbox. It means trainers stay in control of their client relationships, business records, approvals, exports, and AI-assisted workflows. This page summarizes the principles the product is being built around.

Last updated: June 2026

01Security philosophy

A coaching business runs on trust: client relationships, payment history, health context, and years of programming work. FitnessTrainerOS treats protecting that trust as a core product requirement — access boundaries, approvals, exports, and data ownership are designed in from the start, not bolted on later.

02Approval-gated AI

FitnessTrainerOS is designed around human-approved AI workflows. Drafts, check-in replies, renewal saves, reassignment suggestions, and client messages are prepared by AI and reviewed by the trainer or manager before anything is sent. The AI works for the trainer — it does not act autonomously toward clients by default.

03Human review before client-facing actions

Anything a client could see or receive — messages, program changes, billing actions — is designed to pass through an explicit approval step. This protects the trainer's voice, the client relationship, and the business record.

04Access and permissions

Role-based access is a core design requirement: a solo trainer sees their business; a team manager sees roster-wide coverage, capacity, risk, and revenue; a client sees only their own record. Manager permissions, role views, and approval workflows are treated as product features, especially for teams managing multiple trainers and clients.

05Data boundaries

Client data belongs to the coaching relationship it came from. The product is designed so client records are scoped to the right trainer and team, and so business data is not exposed across accounts. Two-sided access (trainer and client viewing one shared record) is permission-aware by design.

06Portability and exports

Business records should be portable. Data export, ownership, and continuity are product principles, not afterthoughts: the standing commitment is that a trainer can take their roster, history, programs, and records with them. Software that traps your business is a security problem of its own kind.

07Public form boundaries

Public website forms are intentionally limited. They are not built for — and must not receive — sensitive client health data, payment credentials, private client records, or confidential business information. Deeper conversations that require that detail happen under separate agreements and channels.

08Infrastructure principles

The product is built on established, professionally operated cloud infrastructure with encrypted connections, managed authentication, environment-isolated secrets, and separation between preview and production environments. Secrets are never embedded in public code or shared through insecure channels.

09Third-party dependencies

Like every modern product, FitnessTrainerOS relies on third-party providers for hosting, authentication, payments, and email. Providers are selected with security posture in mind, and dependencies are kept deliberate and minimal rather than sprawling.

10What we do not claim yet

FitnessTrainerOS is an early-stage product and we will not inflate our security posture. We do not yet claim formal certifications such as SOC 2 or HIPAA compliance. As the product matures toward handling live client data at scale, security commitments will be formalized and documented — and this page will say exactly what is and is not covered.

11Reporting a concern

If you believe you have found a security issue with the website or product, email amin@sharif.global with details. We take good-faith reports seriously and will respond promptly. Please do not publicly disclose an issue before giving us a reasonable chance to address it.

12Private access and additional terms

If a coach is invited into private onboarding, paid service, design partnership, or deeper product access, additional security, confidentiality, and data-processing terms may apply and will be provided in writing as part of that engagement.

This page is provided for transparency and should be reviewed by legal counsel before being relied on as final legal language. Questions about this page can be sent to amin@sharif.global.