| Legal name and entity | Strata Strength LLC, an Ohio limited liability company, formed May 2026. Cincinnati, Ohio. |
| Product | Strata, a web application for athletic medicine and performance: injury and treatment records, concussion protocols, strength programming, nutrition, wellness check-ins, training load, weather safety, and department operations. |
| Security and privacy contact | Michael Gordon, Founder. mgordon@stratastrength.net. The same address is the incident contact. |
| Years in operation, reference customers | Live with schools since the 2026-27 school year. St. Xavier High School (Cincinnati) runs 800+ athletes on Strata and is available as a reference on request. |
| Where is data hosted? | United States cloud regions only. Database and authentication on Supabase (running on Amazon Web Services); application hosting and server functions on Vercel (on AWS); this public website and the public demo on Netlify. No self-managed servers. |
| Is data ever stored outside the US? | No. |
| Certifications held by the vendor | Strata itself has not completed a SOC 2 or ISO 27001 audit. It is on the roadmap and you will hear it from us, not discover it. |
| Certifications held by subprocessors | Supabase: SOC 2 Type II, HIPAA-eligible under BAA. Vercel: SOC 2 Type II. AWS: ISO 27001, SOC 1/2/3. Reports available on request for your files. |
| Full subprocessor list | Published and kept current at stratastrength.net/security, including what each one sees. |
| Multi-tenant? | Yes. Every school is isolated by row-level security enforced in the database itself, keyed on the school's organization ID. One school cannot query another's data even if application code has a bug. |
| Sign-in methods | Google Workspace and Microsoft Entra single sign-on (the school's own accounts); a one-time sign-in code sent to a pre-authorized email; or email and password (12 characters minimum with letters and numbers). One email is one account regardless of the door used. |
| Multi-factor authentication | Authenticator-app (TOTP) two-factor is available on every account and enforced at sign-in for anyone who has enrolled it. Staff in health roles are prompted to enroll. Signing in through the school's Google or Microsoft account satisfies it through the school's own MFA policy. |
| Can anyone sign themselves up? | No open signup. Schools pre-authorize each person's school email, so identity comes from the school's own records. A sign-in from an unrecognized account is rejected. |
| Role-based access | Yes. Roles: Athletic Trainer, physician, strength coach, sport coach, athletic director, administrator, athlete, parent. Coaches see availability status, never the clinical note. The access matrix is published on the security page and documented in full in the whitepaper. |
| Can the school administer its own users? | Yes. School administrators add and remove users, assign roles, scope coaches to sports, and reset a user's two-factor. |
| Session handling | Sessions are long-lived so staff are not re-prompted on every open; a fresh sign-in on a new device requires the second factor where enrolled. Signing out ends the session. |
| Vendor access to customer data | Limited to the founder for support, on request, and logged. No offshore support. No third party has standing access. |
| What data is collected? | Student name, grade or graduation year, school email, parent and emergency contacts, sport and team; injury, treatment, rehabilitation and concussion records; physical clearance status and date; wellness check-in responses; training, testing and nutrition data; optional uploaded documents such as physicals or physician notes. |
| Data we do not collect | No Social Security numbers. No payment card data (fees are tracked as amounts, never as card numbers). No advertising identifiers. |
| Who owns the data? | The school. Strata is a school official under FERPA with a legitimate educational interest, under the school's direct control, and the Data Protection Addendum says so. |
| Is data sold, shared for advertising, or used to build profiles? | No, and it is a signed contractual commitment: no sale, no advertising, no profiling, and no use of student data to train any generally available AI model. |
| Data export | The school can export its data at any time from inside the application, in standard spreadsheet formats. |
| Retention and deletion | Data is retained for the life of the subscription. On termination, Strata makes the data available for export on written request within 30 days and then deletes its copies, subject to legal retention requirements. Uploaded physicals are protected from deletion inside the app while the school is a customer. |
| Audit logging | Sensitive actions are logged with the acting user and timestamp: who viewed, who changed, and when. |
| Secure development | Single codebase, continuous deployment, automated tests that must pass before a build ships, including tests for the data-safety rules (a roster or injury log can never be wiped by a bad sync, a coach can never see another sport's clinical data). A public change log is published for customers. |
| Security headers | Strict-Transport-Security, Content-Security-Policy (object-src none, frame-ancestors self), X-Content-Type-Options nosniff, X-Frame-Options SAMEORIGIN, restrictive Permissions-Policy and Referrer-Policy. |
| Independent testing | An external security specialist reviewed the live application in July 2026. Findings were addressed or scheduled and are tracked in a written hardening plan. No formal penetration-test certificate is held. |
| Vulnerability disclosure | Email mgordon@stratastrength.net. There is no bug bounty program. |
| Rate limiting and abuse protection | Provided at the platform level on sign-in, sign-up and token endpoints. Optional CAPTCHA on sign-in is built in and can be enabled. |
| Cost controls on AI | Server-side caps per day, week and month, and per user. The browser cannot bypass them. |
| Which providers? | Anthropic (Claude) through a server-side proxy; the platform can also be configured for OpenAI. Groq for speech-to-text on voice dictation. The browser's own dictation (Google or Microsoft) where the browser offers it. Each is listed on the security page with what it receives. |
| What data goes to AI? | It depends on the feature, and we say which. Some features send only anonymous numbers. Reading an uploaded document sends the document, and drafting a parent message sends the injury detail. Providers are contracted not to train on it. |
| Can a school keep health information away from AI? | Yes. A no-PHI-to-AI setting is enforced on our server, not just in the browser. A school can also disable AI entirely. Several features are hard-blocked from ever sending health information regardless of settings. |
| Do AI features make clinical decisions? | No. AI never diagnoses, never sets a return-to-play status, never discusses an athlete's weight loss, and routes anything concerning to the school's Athletic Trainer. Every AI suggestion is accepted or dismissed by a person. |
| FERPA | Strata operates under the school-official exception. The school owns and controls the data; use is limited to providing the service; no secondary use. The Data Protection Addendum documents it. |
| HIPAA | For a high school, athletic training records are FERPA education records that HIPAA excludes, so no BAA is required. For a clinic, hospital-run program or any customer that bills insurance, business associate terms are written into Exhibit B of the agreement and signed with it. |
| COPPA | No open signup. Schools authorize each student's account, consistent with the school-authorization framework. AI features are labeled as AI and never pose as a person. |
| State student privacy law | The addendum includes state student-privacy terms and is adapted to the customer's state. We sign district NDPAs, including SDPC-based state agreements. |
| Accessibility | See the accessibility statement. Contrast is measured automatically; a formal VPAT has not been completed and can be prepared on request. |
| Backups | Automated managed database backups, plus a nightly archive of uploaded medical files. Point-in-time recovery is available on our hosting platform as an upgrade and is not yet active. |
| Availability commitment | Commercially reasonable efforts to keep the platform available, scheduled maintenance excluded, per the agreement. A live status page is at stratastrength.net/status. |
| What happens during an outage? | Devices already signed in keep working from a local copy and send changes when the connection returns. Kiosk check-ins queue on the device. New sign-ins are what stops. |
| Breach notification | Prompt notification to the school, consistent with FERPA and Ohio breach-notification law, with a full account of what happened and what is being done. Subprocessors are contractually required to notify Strata of incidents affecting our data. |
| Business continuity | The school can export its data at any time in standard formats, so it is never dependent on Strata's continued operation. Source code is version-controlled off-site. |
| Insurance | The agreement commits Strata to carry cyber liability and technology errors-and-omissions coverage. A certificate naming the district is available on request. |
| Single sign-on | Google Workspace and Microsoft Entra, live. No SAML connector at this time. |
| Rostering | By file: a roster or registration export from any SIS or forms vendor, or a published roster page by its link. Clever, ClassLink and OneRoster are not built yet. |
| Other integrations | Calendar subscriptions (.ics), FinalForms, DragonFly, Rank One, Privit and Aktivate exports, Healthy Roster and TeamBuildr history imports, force plate and timing systems, GPS units, WHOOP and Oura. |
| Mobile | A web application that installs to the home screen on iPhone and Android and runs as an app, with notifications. App Store and Google Play listings are planned and not yet published. |
| Browser support | Current versions of Safari, Chrome, Edge and Firefox on phone, tablet and desktop. |