Trust Center
Enterprise evaluations move faster when the hard questions are already answered. BetterUp’s Trust Center covers the three areas procurement and governance teams care most about — security, data privacy controls, and our responsible AI framework — and connects directly to our Trust Portal for immediate access to audit reports, certifications, pen tests, and policies.
Trusted by security
leaders at top enterprises
Trusted by security
leaders at top enterprises
Built for safe, responsible development.
Grounded in coaching ethics
Our platform is built on professional coaching standards that prioritize member well-being and development.
Confidential by design
Privacy and confidentiality are embedded in every layer of the platform architecture and experience.
Built for quality and safety
BetterUp data is encrypted in transit and at rest using industry-standard methods, including TLS and AES-256. Our approach to AI prioritizes privacy, security, and trust.
Three pillars of protection
Security
Enterprise-grade protection is built into the platform. BetterUp combines rigorous controls, strong encryption, independent testing, and continuous risk management to help protect customer and member data.
Privacy
Designed to protect personal data and human transformation experiences. We apply privacy controls at every layer, and safeguard the confidentiality of coaching interactions across the platform.
Responsible AI
AI with clear boundaries, human oversight, and governance practices designed to support quality and preserve trust.
Security built in, not layered in.
Protecting coaching data isn’t just a feature — it’s a precondition for the platform working at all. We invest in security at every layer: the architecture, the development process, the controls on who can access what, and the independent parties we bring in to find what we've missed. The audits behind our certifications exist to verify one thing: that what we say we do is what we actually do.

Executive and board oversight
BetterUp has an active Information Security Committee (ISC) in place.
The executive leadership and the BetterUp board are given periodic updates on the overall security threats, hygiene, and maturity of the Information Security Program.
Scrutiny-tested certifications
SOC 2 Type II and ISO 27001 aren’t point-in-time claims — they require ongoing independent audits that validate our controls are actually working, year over year. Our current certifications and reports are available through the Trust Portal at trust.betterup.com.
Independently audited
We hire independent third parties to attempt to break into our platform and use what they find to make it stronger. External penetration tests cover applications, services, and infrastructure, with all vulnerabilities tracked through remediation. A summary is available under NDA.
Robust shared security model
BetterUp runs on AWS US and EU regions using a multi-availability zone model, managed through Heroku’s private-space PaaS — which includes a built-in Web Application Firewall. Both AWS and Heroku hold SOC 2 Type II and ISO 27001 certifications.
Privacy that respects everyone.
Coaching only works when people feel safe to be honest. Privacy at BetterUp is an architectural decision, made at the design stage and carried through every product update since. Members engage knowing their sessions are theirs. Organizations get the authentic insights that only come from people who aren’t holding back.
Confidential by design, valuable by result
When members know their sessions are private — not visible to employers or managers — they engage more openly. That quality is what makes coaching transformational. It’s also what makes your anonymized, aggregated organizational data meaningful: you're measuring what people actually think, not just what they're willing to say.
Customer data is not used in model training
Your members’ coaching conversations are never used to train AI models — ours or anyone else's. We back that up contractually: every AI vendor we work with is explicitly prohibited from using coaching session data for model training or any purpose outside of direct service delivery.
Your data, your region
We give organizations a choice of where their data lives — US or EU hosting — so you can meet your regulatory requirements and internal data governance preferences without workarounds. Choose the region that works for your organization; we’ll handle the rest.
We carry the compliance weight
Most enterprise vendors pass privacy obligations back to the customer. BetterUp doesn’t. We manage consent, handle deletion and access requests, maintain audit logs, and absorb the regulatory obligations that come with handling coaching data, so your legal, HR, and governance teams get a platform that's already done the compliance work.
AI built for growth and governed for trust
BetterUp’s AI is purpose-built for human transformation. It is designed around behavioral science, not adapted from a general-purpose model. That distinction shapes how we govern it: our AI systems operate within coaching-specific boundaries; are tested continuously against bias, fairness, ethics, and accuracy criteria; and are overseen by a dedicated safety and ethics program with human review built in.
Safety testing you can see
Our AI is tested continuously — and we publish the results. Our automated safety evaluation system runs hundreds of test scenarios on every code change, surfacing any bias, fairness, ethics, and accuracy issues for immediate remediation. Reports are available to enterprise customers and auditors on request, so you can verify our safety posture rather than take our word for it.
AI built for developing people, not evaluating them
BetterUp’s AI is built for one purpose: helping individuals grow. It doesn’t assess employees for hiring or performance management, doesn’t make decisions that affect someone's employment, and doesn't report individual coaching content or inferences back to their employer. That’s a responsible product choice that pre-dated AI regulations, and it’s what keeps our AI out of the categories that regulators in the US and EU have identified as highest risk. Your employees get a genuine development tool. Your legal team gets one less compliance concern.
Guardrails built for coaching, not just compliance
Every AI coaching conversation runs through a multi-layered Detect-Respond-Monitor framework with specialized classifier agents that act as guardrails to detect issues such as self-harm crises. The system is continuously tuned by our R&D team, and organizations can customize guardrail responses to match their specific HR support infrastructure.
Effectiveness proven by a controlled study, not asserted by marketing
Most AI vendors tell you their product works. We ran a randomized controlled trial to demonstrate it. BetterUp Labs conducted a four-week study with full-time workers, randomly assigned to BetterUp AI coaching, a major LLM provider, or a control group. BetterUp AI Coaching produced statistically significant gains in productivity and AI readiness compared to the major LLM provider, with the strongest effects among participants who were least AI-oriented at the start.
Trust and security
No. BetterUp does not use customer data to train LLMs.
BetterUp publicly references SOC 2 Type II and ISO 27001, along with privacy-related commitments including GDPR and CCPA.
BetterUp uses TLS for data in transit, AES-256 for data at rest, access controls based on least privilege, monitoring, and vulnerability management.
Individual user interactions are confidential and aggregated, anonymized insights are shared only when thresholds are met.
The BetterUp Trust Portal provides access to reports and supporting diligence materials.