HIPAA
Aligned
Controls in build; BAA available on request. Not a completed certification.
Security and privacy
Built around HIPAA, PIPEDA, and GDPR requirements for women's sports teams and women's health clinics. Formal certification is in progress. We will not print a badge we cannot defend.
Compliance
HIPAA
Aligned
Controls in build; BAA available on request. Not a completed certification.
PIPEDA
Aligned
Deletion, correction, and access controls are built. Formal audit has not been undertaken.
SOC 2 Type II
In progress
Scoped against the same control set. There is no report to share yet.
Encryption
In place
AES-256 at rest, TLS 1.3 in transit.
Athlete privacy governance
Access is granted by the athlete. Labs stay off a coach's query. Clinical notes sit on the shared record so the team is looking at the same athlete.
Technical security specifications
AES-256 at rest through KMS on the database, object store, and backups. TLS 1.3 in transit on every API channel.
Clinical records are held in AWS ca-central-1 with private networking, customer-managed encryption keys, and access logs. The API and identity layer follow in the current residency migration.
Each row has a class. A coach's query cannot bind labs. Clinical notes are a shared class on the same athlete, so coach, clinician, and athlete read the same note. Enforcement is at fetch time. A full audit trail of every lab view is on the certification roadmap.