Security

How we keep your data safe.

Protecting athlete and organisation data is core to everything we build. Security is designed into the platform, not bolted on afterwards.

Our practices

  • Encryption in transit (TLS) and at rest for all stored data.
  • Strict tenant isolation — every record is scoped to its organisation.
  • Role-based access control so users only see what their role permits.
  • Signed, HTTP-only session cookies to protect authentication.
  • Continuous monitoring and regular dependency updates.

Subprocessors

A small number of specialist infrastructure providers help us operate SprtIQ, each given access only to what its specific function requires:

  • Vercel — application hosting.
  • Supabase — database hosting (PostgreSQL, on AWS in the EU).
  • Resend — transactional email delivery.
  • Sentry — application error monitoring.
  • Stripe and Twilio — payment processing and SMS/WhatsApp messaging, only for organisations that opt into those specific features.

Reporting a vulnerability

If you believe you've found a security issue, please email info@sprtiq.com. We take all reports seriously and will acknowledge your message promptly.