Security & Compliance

The answers your tech director
screens vendors with.

Strata holds health information about kids and we treat it that way. This page names the specifics: the encryption, the access walls, the subprocessors, the paperwork we sign, and who to call if something ever goes wrong. No vibe language.

The technical floor.

Encryption

TLS 1.2+ on every connection. AES-256 at rest in the database. The app is never served over plain HTTP, and secrets live server-side only, never in the browser.

Two-factor authentication

Available on every account, and enforced at sign-in for anyone enrolled. Staff who can see health information are asked to turn it on and prompted until they do. Signing in with your school Microsoft or Google account satisfies it through the school’s own MFA.

Schools walled off from each other

Isolation is enforced by the database itself with row-level security, not just the interface. One school can never query another's athletes, even if application code has a bug.

Backups & recovery

Managed database backups with point-in-time recovery, plus a nightly archive of uploaded medical files. Uploaded physicals cannot be deleted from inside the app, by anyone.

Audit logging

Sensitive actions are logged: who viewed, who changed, and when. That trail supports both compliance reviews and your standard-of-care documentation.

US hosting

All data is hosted in United States cloud regions on infrastructure from Supabase, Vercel, and AWS.

Who sees what.

Least privilege isn't a slogan, it's a table. Here is the actual access matrix, simplified.

Athletic Trainer S&C Coach Sports Coach AD / Admin Athlete Parent
Clinical medical record (evals, notes, treatments)Full✗✗✗Own record summaryVia AT updates
Availability status (cleared / limited / out)✓✓Own sport only✓OwnOwn child
Concussion protocol detail✓✗✗Stage onlyOwnOwn child, via AT
Performance testing & programming✓✓Own sport✓Own✗
Wellness responsesFullFlags onlyFlags only, own sportParticipation countsOwn✗
Department reports✓Performance only✗De-identified counts✗✗

Simplified summary of the default role model; the whitepaper documents the full matrix. Schools assign roles and can tighten further.

The paperwork, named.

Data Processing Agreement

A plain-English DPA covering data ownership, permitted use, subprocessors, breach notification, and deletion is available on request, before you sign anything. Request it →

Student data privacy agreements

We will sign your district's student-data-privacy agreement, including SDPC-style state agreements. Ohio districts first; ask and we'll work through your state's version.

FERPA

Strata operates under the FERPA school-official model: the school owns and controls the data, use is limited to providing the service, and there is no secondary use.

HIPAA

For high schools these records are generally FERPA education records that HIPAA excludes. We apply HIPAA-grade safeguards regardless, and sign Business Associate Agreements for clinics and other covered entities.

Never sold, in writing

No sale, no advertising, no secondary commercial use of student data. It's a signed contractual commitment, not a website bullet.

Retention & deletion

Export your data any time. On termination we return it and delete our copies on request. Uploaded physicals are protected from deletion while you're a customer.

Subprocessors.

The complete list of third parties that touch data, and what each one sees.

ProviderRoleData it touchesPosture
Supabase (on AWS)Database & authenticationApplication dataSOC 2 Type II, AES-256 at rest, HIPAA-eligible under BAA
Vercel (on AWS)App hosting & server functionsData in transitSOC 2 Type II, automatic TLS, DDoS mitigation
Amazon Web ServicesUnderlying infrastructureHosts the aboveISO 27001, SOC 1/2/3
ResendTransactional emailNames & emails only, no medical dataTLS
Anthropic / OpenAIOptional AI featuresOnly what the task needs. Anonymous numbers for some features; the student’s name and health detail when reading a document or drafting a parent messageServer-side proxy; no training on our data; schools can keep health data away from AI, or disable AI entirely
GroqSpeech‑to‑text for voice dictationThe recorded audio, which can carry health detail if that is what was dictatedServer‑side proxy; dictation is switched off completely in no‑PHI mode
Your browser’s own dictation (Google / Microsoft)The phone or laptop’s built‑in speech recognition, where the browser offers itThe audio, sent to the browser maker rather than to usNot used in no‑PHI mode
corsproxy.io / allorigins.winFallback relay for fetching a public page, such as a league stats page or a school calendar feed, when our own server cannotThe public web address being fetched and that page’s contents. No athlete data passes through themUsed only after our own server is tried first

Subprocessor SOC 2 reports and DPAs are available on request for your district's files. Certifications reflect each provider's published compliance documentation.

Straight answers.

Is Strata SOC 2 certified?
Strata runs entirely on SOC 2 Type II audited infrastructure (Supabase, Vercel, AWS). Strata itself is an early-stage company and has not yet completed its own SOC 2 audit; it's on our roadmap as we grow. In the meantime the whitepaper documents every control we run, and we'll answer any security questionnaire your district uses.
Is Strata a HIPAA covered entity?
For a high school, athletic training records are generally education records governed by FERPA, which HIPAA excludes. So in the school setting, no. We apply HIPAA-grade technical safeguards anyway, and for clinics and other HIPAA-covered customers we sign a Business Associate Agreement.
Who owns the data?
The school. Full stop. You can export it whenever you want, and when you leave, we return it and delete our copies.
Does AI see student information?
It depends on the feature, and we will not pretend otherwise. Some send only anonymous numbers. Others have to send the real thing: reading a doctor’s note, a physical form or a roster means the name on it goes too, and drafting a parent message means the injury detail goes. Whatever is sent, the provider is contracted not to train on it, and a school that wants health data kept away from AI can switch that on, enforced on our server rather than in the browser. They run through a server-side proxy, so no keys or raw data ever sit in a browser. Schools that want zero AI can have it switched off entirely, and several features are hard-blocked from ever sending health information regardless of settings.
What happens if there's a breach?
Prompt notification to the school, consistent with FERPA and Ohio breach-notification law, plus a full account of what happened and what we're doing about it. Incident contact: mgordon@stratastrength.net. You will hear from us, not from the news.
Can students sign themselves up?
No open signup. Schools pre-authorize each student's school email, so identity comes from the school's own records, consistent with COPPA's school-authorization framework. AI features are labeled as AI, never pose as a person, and route anything concerning to the school's Athletic Trainer, a licensed professional.

Put us through your review.

Send your tech director's questionnaire, request the DPA, or grill us on a call. We built this to pass the hard look.