Security & Compliance

The answers your tech director
screens vendors with.

Strata holds health information about kids and we treat it that way. This page names the specifics: the encryption, the access walls, the subprocessors, the paperwork we sign, and who to call if something ever goes wrong. No vibe language.

The technical floor.

Encryption

TLS 1.2+ on every connection. AES-256 at rest in the database. The app is never served over plain HTTP, and secrets live server-side only, never in the browser.

Two-factor authentication

Staff who can see protected health information are required to use two-factor sign-in with an authenticator code. Athletes and parents can turn it on too.

Schools walled off from each other

Isolation is enforced by the database itself with row-level security, not just the interface. One school can never query another's athletes, even if application code has a bug.

Backups & recovery

Managed database backups with point-in-time recovery, plus a nightly archive of uploaded medical files. Uploaded physicals cannot be deleted from inside the app, by anyone.

Audit logging

Sensitive actions are logged: who viewed, who changed, and when. That trail supports both compliance reviews and your standard-of-care documentation.

US hosting

All data is hosted in United States cloud regions on infrastructure from Supabase, Vercel, and AWS.

Who sees what.

Least privilege isn't a slogan, it's a table. Here is the actual access matrix, simplified.

Athletic Trainer S&C Coach Sports Coach AD / Admin Athlete Parent
Clinical medical record (evals, notes, treatments)FullOwn record summaryVia AT updates
Availability status (cleared / limited / out)Own sport onlyOwnOwn child
Concussion protocol detailStage onlyOwnOwn child, via AT
Performance testing & programmingOwn sportOwn
Wellness responsesFullFlags onlyFlags only, own sportParticipation countsOwn
Department reportsPerformance onlyDe-identified counts

Simplified summary of the default role model; the whitepaper documents the full matrix. Schools assign roles and can tighten further.

The paperwork, named.

Data Processing Agreement

A plain-English DPA covering data ownership, permitted use, subprocessors, breach notification, and deletion is available on request, before you sign anything. Request it →

Student data privacy agreements

We will sign your district's student-data-privacy agreement, including SDPC-style state agreements. Ohio districts first; ask and we'll work through your state's version.

FERPA

Strata operates under the FERPA school-official model: the school owns and controls the data, use is limited to providing the service, and there is no secondary use.

HIPAA

For high schools these records are generally FERPA education records that HIPAA excludes. We apply HIPAA-grade safeguards regardless, and sign Business Associate Agreements for clinics and other covered entities.

Never sold, in writing

No sale, no advertising, no secondary commercial use of student data. It's a signed contractual commitment, not a website bullet.

Retention & deletion

Export your data any time. On termination we return it and delete our copies on request. Uploaded physicals are protected from deletion while you're a customer.

Subprocessors.

The complete list of third parties that touch data, and what each one sees.

ProviderRoleData it touchesPosture
Supabase (on AWS)Database & authenticationApplication dataSOC 2 Type II, AES-256 at rest, HIPAA-eligible under BAA
Vercel (on AWS)App hosting & server functionsData in transitSOC 2 Type II, automatic TLS, DDoS mitigation
Amazon Web ServicesUnderlying infrastructureHosts the aboveISO 27001, SOC 1/2/3
ResendTransactional emailNames & emails only, no medical dataTLS
Anthropic / OpenAIOptional AI featuresDe-identified data only, no names, no identifiersServer-side proxy; schools can disable AI entirely

Subprocessor SOC 2 reports and DPAs are available on request for your district's files. Certifications reflect each provider's published compliance documentation.

Straight answers.

Is Strata SOC 2 certified?
Strata runs entirely on SOC 2 Type II audited infrastructure (Supabase, Vercel, AWS). Strata itself is an early-stage company and has not yet completed its own SOC 2 audit; it's on our roadmap as we grow. In the meantime the whitepaper documents every control we run, and we'll answer any security questionnaire your district uses.
Is Strata a HIPAA covered entity?
For a high school, athletic training records are generally education records governed by FERPA, which HIPAA excludes. So in the school setting, no. We apply HIPAA-grade technical safeguards anyway, and for clinics and other HIPAA-covered customers we sign a Business Associate Agreement.
Who owns the data?
The school. Full stop. You can export it whenever you want, and when you leave, we return it and delete our copies.
Does AI see student information?
AI features receive de-identified data only: no names, no identifiers. They run through a server-side proxy, so no keys or raw data ever sit in a browser. Schools that want zero AI can have it switched off entirely, and several features are hard-blocked from ever sending health information regardless of settings.
What happens if there's a breach?
Prompt notification to the school, consistent with FERPA and Ohio breach-notification law, plus a full account of what happened and what we're doing about it. Incident contact: mgordon@stratastrength.net. You will hear from us, not from the news.
Can students sign themselves up?
No open signup. Schools pre-authorize each student's school email, so identity comes from the school's own records, consistent with COPPA's school-authorization framework. AI features are labeled as AI, never pose as a person, and route anything concerning to the school's Athletic Trainer, a licensed professional.

Put us through your review.

Send your tech director's questionnaire, request the DPA, or grill us on a call. We built this to pass the hard look.