Trust & Compliance

Enterprise-grade security
SOC 2 Type II · HIPAA-aligned · BAA-ready.

BioHacker Sports™ handles athlete performance and health information — which means our security posture has to hold up to a medical-department review. We publish our controls, sub-processors, and data-handling posture publicly so your legal team never has to guess.

SOC 2 Type II
Audit in progress
Independent audit covering security, availability, confidentiality, and processing integrity.
HIPAA
HIPAA-aligned
Aligned with the HIPAA Security Rule + Privacy Rule. BAA available on request.
Data residency
Attested
Primary storage: United States. Encrypted at rest (AES-256) + in transit (TLS 1.2+).
SOC 2 controls
  • Access-control policy · least-privilege RBAC
  • Encryption at rest (AES-256) + in transit (TLS 1.2+)
  • Immutable audit log for PHI access + admin actions
  • Vulnerability scanning + patch cadence
  • Vendor risk-management program
  • Change management + code review gates
  • Business continuity + disaster recovery plans
  • Incident response runbook
HIPAA controls
  • PHI classification + tagged data model
  • Consent capture (athlete_consents collection)
  • Minimum-necessary access enforced by role scoping
  • Full audit trail on every PHI-endpoint read/write
  • Encryption at rest + in transit
  • Breach-notification policy · 60-day maximum
  • Data retention policy (see below)
  • Workforce training + confidentiality attestations
Sub-processors
  • MongoDB Atlasprimary data store · US
  • AWS S3video capture storage · US
  • Resendtransactional email · US
  • Stripepayment processing · US
Data-handling policy
  • Residency: United States
  • Retention: 1825 days default
  • Backups: daily · 30 days
  • Encryption: AES-256 at rest, TLS 1.2+ in transit
Published policies
Information Security PolicyAcceptable Use PolicyHIPAA Privacy & Security PoliciesData Retention & Deletion PolicyIncident Response PlanBusiness Continuity & DR PlanVendor Risk Management Policy
Business Associate Agreement

Request a BAA.

If your organization requires a Business Associate Agreement before onboarding, request one here. Our legal team returns a signed BAA within 3 business days.