Security
Athletes trust your staff with their bodies.
Staff trust us with what they say.
Here's how we honor that. No dark patterns, no buried defaults, no claims we can't back up.
Practice
01 · Data residency
Your data stays where we agreed it would.
Athlete biometrics and protocol records sit in US-based, SOC 2 Type II-compliant infrastructure (AWS us-east-1). Region pinning is available on request for federations and enterprise customers with cross-border requirements. We never move your data to a different region without written approval.
02 · Encryption
At rest. In transit. On the device.
Everything in our database is encrypted at rest with AES-256. Everything over the wire uses TLS 1.3. Wearable data pulled from partner APIs lands encrypted and is never written to disk in plaintext. Athlete text messages are routed through carrier-grade gateways and stored encrypted; we do not retain raw message content beyond the protocol acknowledgement.
03 · Consent
Every athlete opts in. Every athlete can opt out.
No athlete is enrolled without explicit consent at signup. Athletes can pause delivery, revoke wearable access, or delete their account at any time with a single text. Staff cannot enroll, re-enroll, or restore an athlete without their fresh consent. Consent records are time-stamped and exportable for audit.
04 · Access controls
Staff see what they need. Nothing else.
Performance directors, head athletic trainers, S&C coaches, and sport psych each get a role-scoped view. Athlete records are gated to staff explicitly assigned to that athlete. Every read and write is logged with a user ID, timestamp, and IP. Logs are retained for the life of the contract plus 1 year.
05 · Wearable partners
We honor the partner agreements you've already signed.
We integrate with Apple HealthKit, Garmin Connect, Oura Ring, Whoop, and Polar via their official APIs. Each integration respects the original partner's terms — including aggregation limits, athlete-facing disclosures, and revocation flows. We do not screen-scrape, proxy, or store data outside of partner-approved patterns.
06 · Roadmap
What we're certifying against next.
SOC 2 Type II audit in progress. HIPAA-aligned controls for collegiate and federation deployments. FERPA controls for collegiate athletic departments handling student-athlete records. ISO 27001 on the roadmap for international federation contracts. We share evidence packets with your IT review under NDA.
Security inquiries
We share evidence packets with your IT review.
Send your security questionnaire, your data processing agreement, or your IT review checklist. We respond within 2 business days with whatever evidence is available, under NDA when needed.
security@soinsai.com→