Security you can verify
Encryption everywhere, SSO for your team, role-based access for every action, and audit logs that record what happened. Built for organizations that take security seriously.
Key Features
Encryption in transit & at rest
TLS 1.2+ for all traffic; AES-256 for data at rest. Organization credentials and integration secrets live in an AES-256-GCM encrypted store, isolated per organization.
Single sign-on
SAML 2.0 and OIDC SSO for your team’s identity provider on paid plans, with custom IdP support on our top-tier plan.
Role-based access
Granular roles for organizers, refs, scouts, finance, and admins. Permissions audit-logged.
Audit logs
Every action timestamped, signed, and exportable. Logs retained per your plan’s retention window.
Security reviews & hardening
Ongoing internal security reviews and hardening passes, including SSRF/IDOR protections and webhook signature verification. Additional detail available under NDA on request.
Vulnerability disclosure
Responsible disclosure guidelines for security researchers. No formal public bounty program, but valid, high-impact findings may be eligible for a reward at our discretion.
How security flows
From request to logged action
Authenticate
Identity verified via SSO or password+MFA.
Authorize
Role-based access checks every action.
Encrypt
Data encrypted in transit and at rest.
Audit log
Action signed and timestamped to log.
Monitor
Anomaly detection runs in the background.
Report
Audit reports available on demand.
Who it’s for
For every security posture
Enterprise
SSO, role-based access, custom DPA, and dedicated infrastructure for large-scale organizations.
Scholastic
FERPA-aware data handling, parental access controls, and minor protection.
Publisher partners
NDAs, custom security reviews, and contractual SLAs for publisher engagements.
FAQ
Security questions
Security questions answered
Talk to our security team for DPAs, our current compliance status, security architecture details, and anything else your procurement needs.
Talk to security team