Security
Your clients’ records stay yours
Therapy notes, children’s details and payments deserve care. This is how Kopli handles them.
Each business is walled off
Every request is checked against the business and branch it belongs to. We test for one business reaching another’s rooms, clients, services or staff, and those tests run on every change.
People see what their role allows
Owner, Admin and Manager roles out of the box, custom roles when you need them, and staff only see the branches they work in.
Every change is recorded
The audit log keeps who created, changed or cancelled a record, and when.
Passwords and sign-in
Passwords are stored as bcrypt hashes, never in plain text. Repeated failed sign-ins and reset requests are rate-limited.
Sessions you can end
Resetting a password signs that account out everywhere. A suspended account is signed out at once.
Kopli staff can’t act as you
Our team can look, never edit your data, and every look is logged. There is no “sign in as this user”. Suspending a business or a person needs a written reason that goes into a log nobody can edit.
This page only says what’s true today
Every line above describes how Kopli works right now. When the product changes, this page changes with it, not before.
Reminders go only where they’re allowed
Clients choose which messages they get and on which channel: push, email or SMS. When a child has no contact details of their own, their reminders go to a guardian.
Set up your first week in an afternoon.
Add your services and rooms, import your client list, and start taking bookings the same day.