Coachpliance is built with security as a foundation — not an afterthought. Here is exactly how we protect your school's compliance records and your coaches' personal information.
Security Practices
All data transmitted between your browser and our servers is protected by HTTPS with TLS 1.2+. Every API call, file upload, login request, and page load is encrypted end-to-end. There are no unencrypted HTTP endpoints.
Certification documents and uploaded files are stored in Amazon S3. AWS S3 applies AES-256 server-side encryption to every object at rest by default. Your coaches' documents are never stored in plain text.
Coachpliance uses OAuth-only authentication. We never ask for, store, or transmit passwords. Login is handled entirely through a secure third-party identity provider, eliminating the most common source of credential breaches.
Every user operates within a strictly scoped role — Coach, School AD, District Admin, or Super Admin. Coaches see only their own data. ADs see only their school. District admins see only their district. Access is enforced at the API layer on every request.
Session tokens are signed with a server-side secret key using JWT. Any modification to a token — even a single character — invalidates it immediately. Sessions expire automatically and cannot be replayed after logout.
We do not sell, rent, or share your data with third parties for advertising or commercial purposes. Data shared with Coachpliance is used solely to provide the compliance tracking service you signed up for.
At a Glance
Contact us directly — we're happy to answer any questions about how we handle your data.
stroup@coachpliance.com