Skip to content

Security

Children are not an ad. They are the file.

This is a database of minors. How it is built is part of the product, not a compliance page.

  • Each league sees its own league

    Every organization is separated in the database, and every query filters on it. There is an automated test that fails if one league can read another league’s data.

  • Medical data doesn’t travel with the roster

    Being able to see a roster doesn’t mean being able to see a medical condition. Those are different permissions, and without permission there is no data.

  • An internal chat doesn’t belong to people who aren’t in it

    An internal conversation is readable only if you are in it. Not even an administrator gets in for being an administrator.

  • The athlete letter isn’t indexed

    The link you share with another league is not picked up by Google. It is a link for a person, not a public page.

  • We prefer archiving to deleting

    A child’s history is not thrown away. An athlete, a team or a season is archived; the file keeps existing.

If you’re going to ask the hard questions, ask them in the walkthrough. We’d rather answer them with the screen open.

See how it’s built, not just how it’s described.

In the walkthrough we open the permissions, the separation between leagues, and what leaves the league.

Book a walkthrough