SECURITY & TRUST

Local connection needs responsible boundaries.

Coqui is being built around verified venues, place-aware room access, privacy-conscious guest participation, and clear operator controls.

CURRENT PRODUCT SAFEGUARDS

Protection at the venue, account, and interaction layers.

Security is not a single feature. It is the way room entry, identity, operations, content, and billing work together.

Place-aware access

QR room tokens and configured proximity checks connect guest entry to an approved physical venue space—not a public global chat.

Privacy-first participation

Guests use temporary Coqui room names and installation-scoped identifiers. The product is designed to avoid requiring public social profiles.

Venue room controls

Authorized venue teams can pause or resume entry, stop guest messaging, clear a room, update the pinned message, and review reported content.

Protected owner workflows

Venue-owner operations use guarded API routes and vendor-scoped authorization. Passwords are stored as salted hashes rather than plaintext.

Safer promotion links

Promotion URLs are validated for public HTTPS destinations before they can be published to the mobile experience.

Feedback safeguards

Quick ratings are limited to once per location every 48 hours. Custom survey rewards unlock for completion, never for a particular answer.

Stripe-hosted billing

Payment methods and supported billing controls are handled in Stripe’s hosted portal. Coqui stores customer references, not full card credentials.

Operational traceability

QR lifecycle, application decisions, and sensitive owner actions are designed to leave auditable operational records.

HONEST BY DESIGN

What Coqui does—and does not—claim today.

The Phoenix pilot is a working product under active hardening. We would rather be specific than imply controls that are not yet production-complete.

Working now

QR/GPS room inspection, hashed venue credentials, guarded owner routes, duplicate-name enforcement, moderation controls, message rate limits, room pause behavior, promotion URL checks, and Stripe test-mode customer portal integration.

Before broad production launch

  • Complete production identity, session revocation, and role-management hardening.
  • Finish migration from remaining demo JSON fallbacks to PostgreSQL-backed data paths.
  • Complete Stripe subscription webhooks and payment-state enforcement.
  • Complete uptime monitoring, backup restore testing, and the incident-response runbook.
  • Expand moderation tooling and abuse-response operations beyond the current report-and-control foundation.

DATA PRINCIPLES

Collect what the experience needs—not a social graph.

Purpose-limited

Room presence, event interest, offer activity, and feedback exist to support the local venue experience and its operations.

Anonymous by default

Survey responses and room participation are designed around device-scoped activity rather than a permanent public guest identity.

Operator boundaries

Venue controls are scoped to the business and its spaces, while corporate workflows handle approvals and broader platform operations.

READY WHEN YOU ARE

Build guest trust from the first scan.

Apply for a verified venue account and keep the experience tied to the place your team actually manages.

Verified venuesStart with one roomScale when ready
Get your venue live No credit card required to apply