Security and Data Protection at Row HQ

Support Area

🚀

Support Area coming soon

Athletic Department-Grade Security

Roster Data You Can Trust to Lock Down

Athletic departments hand us sensitive student-athlete information, so we treat it like a vendor security questionnaire reviewer would. Strong cryptography, access boundaries that respect FERPA, and transparent answers when your AD or compliance office asks how a roster vendor handles its data.

AES-256 + TLS 1.3

Cryptography

UK Cloud

London Region

CCPA + FERPA Aware

US Privacy Posture

99.9%

Platform Uptime

How a Roster Vendor Should Handle Your Data

Each layer mapped to what athletic department procurement reviewers ask about

Strong Cryptography

Every connection rides over TLS 1.3, and the database sits behind AES-256 encryption at rest. The cryptography section of a SIG-style vendor questionnaire is the kind of plain-answer detail we are happy to fill in.

  • TLS 1.3 across web, API, and mobile traffic
  • AES-256 database encryption at rest
  • Encrypted backup volumes

UK-Based Cloud Hosting

Production workloads run in a cloud data centre in London, under UK GDPR jurisdiction. We do not operate a US-region tenancy today, so roster data crosses the border under the standard contractual safeguards US programs typically accept from a UK-based processor. If your athletic department's procurement office treats UK hosting as a non-starter, raise it before signup and we will walk your compliance reviewer through the transfer documentation.

  • Enterprise cloud data centre in London
  • UK GDPR jurisdiction with documented controls
  • Standard cross-border transfer paperwork on request

FERPA-Aware Access Boundaries

Student-athlete records under FERPA need a defined need-to-know path, so our role model separates head coach, assistant coach, athletic trainer, AD compliance officer, and athlete-facing portals. Each role sees only the columns its job demands. Title IX participation reporting can be exported by the AD without exposing individual records to coaches who do not need them.

  • FERPA-style role separation across the roster
  • Bcrypt password hashing with per-account salts (12 rounds)
  • Idle session expiry tunable by the athletic department

Restorable Roster Snapshots

Roster snapshots run nightly into separate backup volumes, plus point-in-time recovery on the database engine itself. Restoring from yesterday's snapshot is straightforward if a corrupted import or accidental deletion of a recruiting class ever needs to be undone.

  • Nightly snapshot backups
  • Thirty-day rolling retention window
  • Point-in-time recovery
Built for AD Procurement Review

CCPA, FERPA, and Title IX Posture

Row HQ ships with the day-to-day controls a US athletic department procurement office wants to see from a roster vendor. We honor California Consumer Privacy Act and CPRA rights for any California resident on a roster, our access boundaries respect FERPA so college programs can document how we handle education records, and Title IX participation totals export cleanly without leaking individual identities. We are not SOC 2 attested today, and we do not claim otherwise - if your procurement office requires a formal attestation report, raise it before signup.

  • CCPA / CPRA Athlete Rights

    California athletes can request access, portability, correction, and deletion of their personal information through the portal

  • Documented Consent Capture

    Recruiting and roster onboarding capture explicit consent timestamps for review by AD compliance

  • Roster Data Minimization

    We collect only the fields a coach or AD needs to run the program, never selling roster data and never enriching it from third-party sources

  • FERPA-Aware by Design

    Education-record handling is built into the schema, not patched in after a procurement review flags it

Athlete Privacy Toggles

Cell number visible to coaching staff
School email visible to lineup peers
DOB visible to athletic trainers
Home address restricted to AD compliance

Athletes manage their own visibility from the portal

Need a Vendor Security Questionnaire?

Send us your AD compliance form, SIG Lite, or data sharing agreement and we will turn it around with a current control inventory and our sub-processor list

Start Free