Effective Date: August 8, 2026
This Information Security Policy establishes the framework for protecting RepLogix systems, data, and operations. It defines the principles, responsibilities, and controls that govern information security across the organization and its platform infrastructure.
This policy applies to all RepLogix personnel (employees, contractors, interns), systems, applications, networks, and third-party service providers that process, store, or transmit RepLogix or customer data. It supports our commitment to protecting athlete, coach, school, and district data in alignment with FERPA, COPPA, and our broader compliance roadmap toward ISO 27001 and SOC 2 Type II.
RepLogix follows these core security principles:
Information security responsibilities are assigned as follows:
All personnel receive security awareness training appropriate to their role:
Onboarding:
Offboarding:
RepLogix conducts risk assessments at least annually and when significant changes occur:
See our Risk Assessment document for the current assessment.
RepLogix maintains an inventory of information assets including:
Each asset is assigned an owner, classification level, and risk rating. The inventory is reviewed quarterly.
Data is classified into the following categories:
RepLogix maintains a data-flow diagram that maps how data moves through the system:
The data-flow diagram is reviewed and updated when architecture changes occur.
This Information Security Policy is reviewed at least annually and updated when significant changes to the organization, systems, or threat landscape occur. The Security Lead is responsible for maintaining and communicating updates.
For questions about this policy, contact: