Roster Data You Can Trust to Lock Down
Athletic departments hand us sensitive student-athlete information, so we treat it like a vendor security questionnaire reviewer would. Strong cryptography, access boundaries that respect FERPA, and transparent answers when your AD or compliance office asks how a roster vendor handles its data.
AES-256 + TLS 1.3
Cryptography
UK Cloud
London Region
CCPA + FERPA Aware
US Privacy Posture
99.9%
Platform Uptime
How a Roster Vendor Should Handle Your Data
Each layer mapped to what athletic department procurement reviewers ask about
Strong Cryptography
Every connection rides over TLS 1.3, and the database sits behind AES-256 encryption at rest. The cryptography section of a SIG-style vendor questionnaire is the kind of plain-answer detail we are happy to fill in.
- TLS 1.3 across web, API, and mobile traffic
- AES-256 database encryption at rest
- Encrypted backup volumes
UK-Based Cloud Hosting
Production workloads run in a cloud data centre in London, under UK GDPR jurisdiction. We do not operate a US-region tenancy today, so roster data crosses the border under the standard contractual safeguards US programs typically accept from a UK-based processor. If your athletic department's procurement office treats UK hosting as a non-starter, raise it before signup and we will walk your compliance reviewer through the transfer documentation.
- Enterprise cloud data centre in London
- UK GDPR jurisdiction with documented controls
- Standard cross-border transfer paperwork on request
FERPA-Aware Access Boundaries
Student-athlete records under FERPA need a defined need-to-know path, so our role model separates head coach, assistant coach, athletic trainer, AD compliance officer, and athlete-facing portals. Each role sees only the columns its job demands. Title IX participation reporting can be exported by the AD without exposing individual records to coaches who do not need them.
- FERPA-style role separation across the roster
- Bcrypt password hashing with per-account salts (12 rounds)
- Idle session expiry tunable by the athletic department
Restorable Roster Snapshots
Roster snapshots run nightly into separate backup volumes, plus point-in-time recovery on the database engine itself. Restoring from yesterday's snapshot is straightforward if a corrupted import or accidental deletion of a recruiting class ever needs to be undone.
- Nightly snapshot backups
- Thirty-day rolling retention window
- Point-in-time recovery
CCPA, FERPA, and Title IX Posture
Row HQ ships with the day-to-day controls a US athletic department procurement office wants to see from a roster vendor. We honor California Consumer Privacy Act and CPRA rights for any California resident on a roster, our access boundaries respect FERPA so college programs can document how we handle education records, and Title IX participation totals export cleanly without leaking individual identities. We are not SOC 2 attested today, and we do not claim otherwise - if your procurement office requires a formal attestation report, raise it before signup.
-
CCPA / CPRA Athlete Rights
California athletes can request access, portability, correction, and deletion of their personal information through the portal
-
Documented Consent Capture
Recruiting and roster onboarding capture explicit consent timestamps for review by AD compliance
-
Roster Data Minimization
We collect only the fields a coach or AD needs to run the program, never selling roster data and never enriching it from third-party sources
-
FERPA-Aware by Design
Education-record handling is built into the schema, not patched in after a procurement review flags it
Athlete Privacy Toggles
Athletes manage their own visibility from the portal
Public Documents
Everything an AD compliance office wants to read before signing
Need a Vendor Security Questionnaire?
Send us your AD compliance form, SIG Lite, or data sharing agreement and we will turn it around with a current control inventory and our sub-processor list