Security and privacy

Athlete-controlled privacy. Encryption in place.

Built around HIPAA, PIPEDA, and GDPR requirements for women's sports teams and women's health clinics. Formal certification is in progress. We will not print a badge we cannot defend.

Compliance

HIPAA

Aligned

Controls in build; BAA available on request. Not a completed certification.

PIPEDA

Aligned

Deletion, correction, and access controls are built. Formal audit has not been undertaken.

SOC 2 Type II

In progress

Scoped against the same control set. There is no report to share yet.

Encryption

In place

AES-256 at rest, TLS 1.3 in transit.

Athlete privacy governance

Athletes maintain ownership of their personal health data.

Access is granted by the athlete. Labs stay off a coach's query. Clinical notes sit on the shared record so the team is looking at the same athlete.

Technical security specifications

  • Data Encryption

    AES-256 at rest through KMS on the database, object store, and backups. TLS 1.3 in transit on every API channel.

  • Infrastructure

    Clinical records are held in AWS ca-central-1 with private networking, customer-managed encryption keys, and access logs. The API and identity layer follow in the current residency migration.

  • Role-Based Access Control (RBAC)

    Each row has a class. A coach's query cannot bind labs. Clinical notes are a shared class on the same athlete, so coach, clinician, and athlete read the same note. Enforcement is at fetch time. A full audit trail of every lab view is on the certification roadmap.