Back to home

Resources

Security & compliance

Enterprise-grade security built for university IT review, procurement, and NCAA compliance requirements.

SOC2 Type II

Annual third-party audit of security controls

FERPA-ready

Service provider model for student-athlete records

US data residency

Customer data stored in US-based data centers

DPA available

Data Processing Addendum on request for institutional customers

Certifications & compliance

Tracker maintains SOC2 Type II compliance with annual third-party audit of security, availability, and confidentiality controls.

Our platform is designed for NCAA-compliant data handling practices required by collegiate athletic departments.

For programs subject to FERPA, Tracker operates as a service provider / school official under the institution's direction. Customer Data including education records remains owned by the institution.

We support institutional requirements for student privacy and biometric privacy laws applicable to athlete data.

Accessibility: we are working toward WCAG 2.1 AA conformance across customer-facing platform surfaces.

Encryption & data protection

All data in transit is encrypted using TLS 1.2 or higher.

All data at rest is encrypted using AES-256.

Encryption keys are managed through our cloud infrastructure provider with regular rotation.

Customer Data — including game film, roster records, statistics, and financial models — is never sold or used to train models for other customers without explicit agreement.

Access controls & authentication

Role-based access control (RBAC) restricts data visibility by user role within your organization.

Multi-factor authentication (MFA) is available for all accounts and recommended for administrative users.

Administrative and privileged access is logged, monitored, and reviewed.

Accounts are provisioned and deprovisioned per customer request. Customers are responsible for credential security within their organization.

Infrastructure & availability

Production infrastructure runs on enterprise cloud providers with US-based data residency.

GPU and compute workloads for Vision Core are isolated from customer-facing application tiers.

We target 99.9%+ platform availability for production deployments.

Infrastructure is managed as code with change control, automated deployment pipelines, and environment separation between development, staging, and production.

Logging, monitoring & incident response

Centralized logging, metrics, and alerting cover platform services, API endpoints, and infrastructure health.

We maintain a documented incident response plan with defined escalation paths.

If we become aware of a security breach affecting Customer Data, we notify affected customers without undue delay and cooperate in good faith to address it.

Affected customers are notified within 72 hours of confirmed breaches where required by applicable regulations.

Data retention & deletion

Retention policies follow your subscription agreement. On termination, customers receive a reasonable opportunity to export Customer Data.

Deletion requests are processed within 30 days of account termination, except for copies required by law or legitimate business records.

Anonymized, aggregated data that does not identify your program or athletes may be used to improve models and the Service.

Vendor & subprocessor management

Third-party subprocessors undergo security review before integration and are bound by contractual data protection terms.

A current subprocessor list is available upon request for university IT and procurement reviews.

We evaluate cloud providers, email delivery, and infrastructure vendors against our security requirements before onboarding.

Application security

Secure development practices include code review, dependency monitoring, and environment separation.

Vulnerability remediation follows a risk-based prioritization framework.

Penetration testing and security assessments are conducted on a regular cadence and before major releases.

Customers agree not to reverse-engineer, scrape, or extract source code or models — and we protect the platform accordingly.

Third-party service providers

A complete subprocessor list with vendor names is available upon request for vendor security reviews. Summary of categories below.

Vendor
Location
Cloud infrastructure (OCI / AWS)
United States
Email delivery
United States
Monitoring & observability
United States

IT & procurement FAQ

Can we sign a Data Processing Addendum (DPA)?

Yes. We provide a DPA for institutional customers upon request, covering FERPA-aligned handling of student-athlete data and standard processor obligations.

Where is our data stored?

Customer Data is stored in US-based data centers. Data residency details for your specific deployment are available during procurement.

Do you use our film or roster data to train models for other customers?

No. Your proprietary film and roster data is not used to train models for other customers without explicit agreement. We may use de-identified, aggregated data to improve the Service.

How do you handle student-athlete records under FERPA?

Tracker acts as a service provider under the institution's direction. The institution retains ownership of education records. We use student-athlete data only to provide the Service, consistent with applicable laws.

Can you complete our vendor security questionnaire?

Yes. Email [email protected] with your questionnaire. We typically respond within 5 business days for standard university IT reviews.

What happens to our data if we cancel?

You may export Customer Data during a reasonable window after termination. We delete retained data per our retention policy, except where legally required to preserve copies.

Vendor security review

University IT and procurement teams can request the following documentation. We typically respond within 5 business days.

  • SOC2 Type II report (under NDA)
  • Subprocessor list
  • Data Processing Addendum (DPA)
  • Architecture overview for IT review
  • Incident response summary
  • Penetration test executive summary