Ir al contenido
Security · Resilience · Trust

Security built into the way we connect your business.

Explore how Kool&Tech approaches identity, data protection, secure implementation, integrations, incident response, recovery, and shared responsibility across Odoo, Microsoft 365, websites, automation, and technology services.

Effective: September 19, 2026 Kool&Tech LLC · FL Document L24000173044 Florida, United States
Controlled accessLeast privilege, MFA, and identifiable accounts where supported.
Secure deliveryTesting, controlled changes, validation, and documented scope.
Data protectionPlatform security, minimization, retention, and recovery planning.
Shared responsibilityClear boundaries across Kool&Tech, clients, and vendors.
Trust through clarity: Security controls vary by service, hosting model, software license, client requirements, and written scope. The applicable proposal, SOW, support agreement, DPA, or security addendum defines project-specific commitments.
Control Area 01

Security overview

Kool&Tech approaches security as a shared business and technical responsibility across consulting, Odoo, Microsoft 365, websites, integrations, automation, development, and support services.

Security measures are selected according to scope, platform, hosting model, data sensitivity, client requirements, available licensing, and the written agreement. No security program can eliminate every risk, but clear ownership, controlled access, careful configuration, testing, monitoring, and recovery planning can reduce exposure and improve resilience.

Security boundary: This Trust Center describes Kool&Tech's approach and the controls that may be applied within an engagement. A control is not included in every project unless it is part of the applicable scope, platform capability, subscription, configuration, or signed agreement.
Control Area 02

Security governance

Security considerations are incorporated into service discovery, solution design, access planning, configuration, development, testing, deployment, documentation, and support.

Risk-based decisionsControls are evaluated against business impact, likelihood, data sensitivity, operational dependency, and platform responsibility.
Defined ownershipResponsibilities are assigned between Kool&Tech, the client, hosting providers, software vendors, and other authorized parties.
Documented scopeSecurity deliverables, exclusions, assumptions, and client obligations are defined through proposals, SOWs, support agreements, or project records.
Continuous improvementPractices may evolve as services, threats, platforms, laws, and contractual requirements change.
Control Area 03

Shared responsibility model

Security outcomes depend on multiple parties. Kool&Tech is responsible for the controls expressly assigned to Kool&Tech. Clients remain responsible for controls under client ownership, including authorized use, data classification, legal authority, internal policies, end-user behavior, approval rules, business continuity, and acceptance of production changes.

  • Kool&Tech: agreed configuration, development, integration, documentation, access discipline, and project activities.
  • Client: users, devices, business rules, data accuracy, role approvals, internal controls, lawful processing, testing, and timely access removal.
  • Platform provider: infrastructure and product controls described in the provider's own documentation and agreement.
  • Other vendors: their applications, APIs, availability, security, support, and contractual commitments.
Control Area 04

Identity and access management

Access is planned around least privilege, business need, role separation, identifiable accounts, and controlled administrative permissions.

  • Role-based access and permissions are configured where supported and included.
  • Multifactor authentication is recommended and may be required for administrative, remote, cloud, and sensitive access.
  • Privileged access should be limited, reviewed, and separated from normal daily-use accounts when the platform supports it.
  • Shared credentials, permanent passwords in email, excessive permissions, and unmanaged service accounts should be avoided.
  • Access should be removed promptly when employment, assignment, vendor relationships, or project needs end.

The client approves its users, roles, segregation-of-duties model, and access rules unless a signed agreement assigns that function to Kool&Tech.

Control Area 05

Credentials, secrets, and authentication

API keys, tokens, certificates, application secrets, administrator credentials, and recovery methods are treated as sensitive access material.

  • Secrets should be stored using platform-provided or approved secure mechanisms rather than source code, public files, or general documentation.
  • Credentials should be unique, scoped to required permissions, and rotated when exposure or personnel changes are suspected.
  • Client-owned accounts and secrets remain under client ownership unless a managed-services agreement states otherwise.
  • Kool&Tech may refuse insecure credential-sharing methods or access arrangements that create unreasonable risk.
Control Area 06

Data protection

Data protection measures depend on hosting, licensing, platform capabilities, information type, and contracted scope.

Data in transitHTTPS, TLS, VPNs, secure APIs, and vendor-provided encrypted channels may be used where supported.
Data at restPlatform, cloud, database, disk, backup, or application encryption may be used where available and configured.
Data minimizationProjects should use only the information reasonably necessary for the authorized purpose.
RetentionRetention and deletion depend on client instructions, contracts, platform settings, backups, legal requirements, and operational needs.

Kool&Tech relies on established encryption supplied by reputable platforms and libraries rather than representing that Kool&Tech creates a proprietary cryptographic framework.

Control Area 07

Data classification and handling

Clients should identify confidential, regulated, financial, health, payment, government, export-controlled, personal, or other sensitive information before transfer or processing.

Highly sensitive data should not be sent through general website forms, ordinary SMS, or unsecured email unless the channel and processing are expressly approved. Additional controls, a DPA, a Business Associate Agreement, data-residency terms, or a specialized platform may be required for regulated information.

Kool&Tech may decline, isolate, delete, or request a safer transfer method for information received outside the approved scope.

Control Area 08

Microsoft 365 security

For Microsoft 365 engagements, security may include identity configuration, multifactor authentication, administrative role hygiene, Conditional Access where licensed, Exchange protections, device management, Microsoft Defender capabilities, data-protection features, and user guidance.

Available controls vary by Microsoft license, tenant configuration, geography, and client requirements. Microsoft operates the underlying cloud services under Microsoft's terms and security commitments. The client remains responsible for assigned administrators, licensing, user lifecycle, device compliance, data governance, and acceptance of recommended settings.

Control Area 09

Odoo security

Odoo security responsibilities depend on whether the environment uses Odoo Online, Odoo.sh, on-premises hosting, or another provider.

  • Application access may use groups, access rights, record rules, user-specific permissions, and authentication controls.
  • Custom modules, Studio changes, automated actions, integrations, and third-party add-ons can change the security boundary and require testing.
  • Odoo-managed hosting controls are provided by Odoo under Odoo's documentation and agreements.
  • Self-hosted environments require separate responsibility for servers, operating systems, databases, networks, TLS, patching, backups, monitoring, and recovery.

Kool&Tech does not claim ownership of Odoo's infrastructure controls or extend Odoo Cloud representations to a self-hosted installation.

Control Area 10

Secure development and change control

Development and integration work may use separation of development, staging, and production; source control; peer or technical review; controlled deployment; testing; validation; logging; and rollback planning according to project scope.

  • Inputs and outputs should be validated and appropriately encoded.
  • Credentials and secrets should not be committed to source control.
  • Dependencies and third-party components should be selected and maintained in line with project requirements.
  • Production changes should be authorized, tested, documented, and deployed through a controlled process.
  • Security-sensitive defects are prioritized according to risk, reproducibility, exposure, and available remediation.
Control Area 11

API and integration security

Integrations are designed around documented endpoints, authenticated requests, least-privilege scopes, validation, error handling, traceability, and controlled data movement where supported.

  • OAuth, tokens, API keys, certificates, webhooks, and vendor authentication methods may be used according to the connected platform.
  • Rate limits, retries, idempotency, duplicate prevention, timeout handling, and failure notifications are considered when included in scope.
  • Clients must approve what data moves, between which systems, for what purpose, and under which account ownership.
  • Changes to third-party APIs, schemas, authentication, pricing, or availability may require maintenance or redevelopment.
Control Area 12

Devices and remote access

Remote work and administrative access should use managed or approved devices, current software, screen locking, endpoint protection, supported browsers, secure networks, and multifactor authentication where applicable.

When client policies require device enrollment, VPN, conditional access, or privileged access workstations, those requirements must be documented and technically available. Clients control endpoint and network security unless expressly assigned to Kool&Tech.

Control Area 13

Vendor and subprocessor risk

Kool&Tech may depend on cloud, hosting, software, communications, payment, analytics, development, and support providers. Vendor selection considers the service purpose, information involved, access required, operational dependency, available contractual commitments, and platform suitability.

Each provider remains responsible for its own products, infrastructure, security, privacy, uptime, and support. Kool&Tech may replace a vendor or adjust an architecture when necessary for security, availability, functionality, compliance, or business reasons, subject to applicable agreements.

Control Area 14

Backups and recovery

Backup responsibility must be assigned in the applicable agreement. Unless a managed backup service is expressly included, the client is responsible for maintaining current, tested, recoverable backups before configuration, migration, upgrade, deployment, integration, or destructive action.

Where backups are provided by a hosting vendor, retention, replication, restore capability, recovery objectives, and availability are governed by that vendor's service. A backup is not considered fully validated until restoration has been tested in an appropriate environment.

Disaster recovery, high availability, geographic redundancy, RPO, and RTO commitments apply only when expressly documented.

Control Area 15

Business continuity and resilience

Kool&Tech plans service delivery around remote operations, documented project records, controlled repositories, vendor-supported platforms, and reasonable recovery options appropriate to the engagement.

Business continuity depends on client systems, personnel, internet, power, cloud services, vendors, credentials, licenses, backups, and third-party availability. Clients should maintain their own continuity plans, emergency contacts, manual procedures, and recovery priorities.

Control Area 16

Logging, monitoring, and auditability

Logging and monitoring may be configured for authentication, administrative activity, integrations, automation failures, application events, infrastructure, or security alerts where supported and included.

Log availability, detail, retention, immutability, export, and alerting vary by platform and license. Logs are not guaranteed to capture every event, prove intent, satisfy a regulatory audit, or remain available indefinitely unless expressly agreed.

Clients should identify audit, evidentiary, retention, and regulatory requirements before implementation.

Control Area 17

Vulnerability and patch management

Security updates and vulnerability handling depend on product ownership and hosting responsibility.

  • Vendor-managed SaaS and cloud providers generally control underlying platform patching.
  • Self-hosted systems require assigned responsibility for operating systems, databases, dependencies, applications, firewalls, certificates, and infrastructure.
  • Custom code or integrations may require assessment, remediation, regression testing, and deployment under a support or maintenance scope.
  • Unsupported software, abandoned modules, and unmaintained dependencies may be rejected or require replacement.
Control Area 18

Incident response

When a suspected security incident is identified within Kool&Tech's responsibility, response activities may include triage, containment, preservation of relevant information, investigation, eradication, recovery, documentation, and communication according to severity, available facts, law, contract, and platform responsibility.

Clients must promptly report suspected account compromise, unauthorized access, malware, exposed secrets, anomalous behavior, data disclosure, or material outages affecting supported systems. Clients should avoid deleting evidence or making uncoordinated changes that could interfere with investigation.

Notices to affected parties, regulators, insurers, law enforcement, or vendors are handled by the legally responsible party, with cooperation allocated by contract and applicable law.

Control Area 19

Vulnerability reporting

Security researchers, customers, and users may report a suspected vulnerability to info@koolandtech.com with the subject “Security Vulnerability Report.”

Please include the affected service, description, reproduction steps, impact, supporting evidence, and safe contact information. Do not access unrelated data, disrupt services, use social engineering, demand payment, publicly disclose an unresolved issue, or exceed the minimum testing necessary to demonstrate the concern.

Kool&Tech will evaluate reports in good faith but does not promise a bounty, payment, safe harbor beyond applicable law, a specific response time, or acceptance of every report.

Control Area 20

Personnel and operational safeguards

Access to client systems and information is limited to authorized people with a business need, subject to role, project, platform, and contractual requirements.

Operational safeguards may include confidentiality obligations, onboarding and offboarding, access review, security awareness, approved tools, separation of responsibilities, documented procedures, and escalation channels.

Clients remain responsible for equivalent controls over client personnel, contractors, devices, facilities, and accounts under client control.

Control Area 21

Physical security

Kool&Tech primarily relies on reputable cloud and SaaS providers for data-center physical security. The physical, environmental, facility, and infrastructure controls of those data centers are operated by the relevant provider.

For onsite work, access is subject to client facility rules. Clients are responsible for physical access to client offices, servers, devices, media, networks, and records unless expressly assigned otherwise.

Control Area 22

Privacy and data processing

Personal information is handled according to the Kool&Tech Privacy Policy, applicable contracts, and any required Data Processing Addendum. The roles of controller, processor, business, and service provider depend on the actual processing activity.

International data transfers, localization, regulated data, data-subject requests, retention, and subprocessor terms may require additional documentation. Clients must disclose relevant requirements before services begin.

Control Area 23

Compliance and assurance

Kool&Tech aligns security planning with recognized risk-management and secure-by-design concepts when appropriate to the engagement. This page does not represent that every control in a named framework is implemented, audited, or certified.

Unless a current certificate or report is expressly published or supplied in writing, Kool&Tech does not claim SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP, CMMC, or another independent certification or attestation.

Client compliance depends on the client's organization, legal obligations, policies, people, data, implementation, vendor contracts, licensing, and ongoing operation. Technology configuration alone does not make a client compliant.

Control Area 24

Client security responsibilities

  • Identify legal, regulatory, contractual, insurance, and data-residency requirements before contracting.
  • Approve users, roles, administrators, segregation of duties, and access changes.
  • Maintain secure devices, networks, email, identity systems, and recovery methods.
  • Keep accurate system owners, emergency contacts, vendor accounts, licenses, and payment methods.
  • Perform user acceptance testing and review security-sensitive settings before production use.
  • Maintain backups and continuity measures unless assigned to Kool&Tech in writing.
  • Report incidents, personnel changes, lost devices, exposed credentials, and suspicious activity promptly.
  • Use systems lawfully and train users on applicable policies.
Control Area 25

Security documentation requests

Prospective and current clients may request available security information relevant to a proposed or active engagement. Kool&Tech may provide public documentation, scoped questionnaire responses, architecture information, contractual terms, or other reasonable evidence subject to confidentiality, security, relevance, and available resources.

Kool&Tech may decline requests that seek internal secrets, unrelated client information, exploit details, excessive disclosure, unsupported warranties, or commitments outside the proposed scope. Extensive questionnaires, audits, custom evidence packages, or onsite assessments may require a separate agreement and fee.

Control Area 26

Trust Center updates

This Security & Trust Center may be updated as Kool&Tech services, platforms, vendors, controls, risks, and contractual practices evolve. The effective date identifies the current public version.

A website update does not amend a signed agreement unless the agreement permits the update or the parties accept it. Contract-specific security commitments must be documented in the applicable agreement.

Security contact available

Security questions or vulnerability reports?

Contact Kool&Tech for security questionnaires, project security requirements, responsible vulnerability reports, or concerns involving a Kool&Tech-managed engagement.

Kool&Tech LLC · Florida Limited Liability Company · United States

  Back to Security & Trust Center