Back to Compliance

RepLogix Information Security Policy

Effective Date: August 8, 2026

This Information Security Policy establishes the framework for protecting RepLogix systems, data, and operations. It defines the principles, responsibilities, and controls that govern information security across the organization and its platform infrastructure.

1. Purpose and Scope

This policy applies to all RepLogix personnel (employees, contractors, interns), systems, applications, networks, and third-party service providers that process, store, or transmit RepLogix or customer data. It supports our commitment to protecting athlete, coach, school, and district data in alignment with FERPA, COPPA, and our broader compliance roadmap toward ISO 27001 and SOC 2 Type II.

2. Security Principles

RepLogix follows these core security principles:

  • Least Privilege: Users and systems receive only the access necessary to perform their function
  • Defense in Depth: Multiple layers of security controls protect critical assets
  • Data Minimization: We collect and retain only the data necessary to provide the Service
  • Continuous Improvement: Security controls are regularly reviewed and improved
  • Shared Responsibility: Security is the responsibility of all personnel, not just the security team

3. Roles and Responsibilities

Information security responsibilities are assigned as follows:

  • Management: Approves security policies, allocates resources, and ensures organizational alignment
  • Security Lead: Maintains policies, conducts risk assessments, coordinates incident response, and oversees compliance efforts
  • Developers: Follow secure development practices, report vulnerabilities, and implement security controls
  • All Personnel: Comply with security policies, complete training, and report suspicious activity

4. Security Awareness Procedures

All personnel receive security awareness training appropriate to their role:

  • New personnel complete security onboarding training before receiving system access
  • Annual refresher training covers phishing, password hygiene, data handling, and incident reporting
  • Role-specific training is provided for developers (secure coding), administrators (access management), and support staff (data privacy)
  • Phishing simulation exercises are conducted periodically to reinforce awareness
  • Training completion is tracked and recorded

5. Employee and Contractor Onboarding/Offboarding

Onboarding:

  • Background checks are conducted for personnel with access to sensitive systems or data
  • Access requests are submitted, approved, and provisioned following least-privilege principles
  • Security training is completed before access is granted
  • Confidentiality and acceptable use acknowledgments are signed

Offboarding:

  • All system access is revoked within 24 hours of termination or role change
  • Company-issued devices, credentials, and access tokens are returned or deactivated
  • Accounts are disabled and reviewed to ensure no residual access remains
  • An offboarding checklist is completed and retained

6. Risk Assessment

RepLogix conducts risk assessments at least annually and when significant changes occur:

  • Assets are identified and classified by criticality and sensitivity
  • Threats and vulnerabilities are evaluated for likelihood and impact
  • Risk treatment plans are documented (mitigate, transfer, accept, or avoid)
  • Residual risk is reviewed by management and tracked to remediation

See our Risk Assessment document for the current assessment.

7. Asset Inventory

RepLogix maintains an inventory of information assets including:

  • Applications and software services (RepLogix app, admin tools, analytics)
  • Infrastructure components (hosting platform, databases, APIs)
  • Data repositories (production database, backups, logs)
  • Endpoints and devices used by personnel
  • Third-party services and subprocessors

Each asset is assigned an owner, classification level, and risk rating. The inventory is reviewed quarterly.

8. Data Classification

Data is classified into the following categories:

  • Public: Marketing content, published policies — no access restrictions
  • Internal: Operational data, non-sensitive business information — authorized personnel only
  • Confidential: Customer data, athlete records, billing information — restricted access, encryption required
  • Restricted: Credentials, secrets, keys — highest protection, need-to-know access only

9. Data-Flow Diagram

RepLogix maintains a data-flow diagram that maps how data moves through the system:

  • User Input: Coaches/admins enter data via web or mobile app → TLS encrypted → RepLogix application layer
  • Application Layer: Data validated and processed → stored in encrypted database (Base44 infrastructure, US-based)
  • Payment Flow: Checkout initiated → Stripe payment processing → metadata returned to RepLogix (no card numbers stored)
  • Notifications: Email/SMS notifications → Resend/Twilio subprocessors → delivered to users
  • Backups: Database → encrypted backups within Base44 infrastructure (US-based)
  • Exports: CSV/report exports → downloaded by authorized users → data leaves RepLogix system

The data-flow diagram is reviewed and updated when architecture changes occur.

10. Policy Review

This Information Security Policy is reviewed at least annually and updated when significant changes to the organization, systems, or threat landscape occur. The Security Lead is responsible for maintaining and communicating updates.

11. Contact

For questions about this policy, contact:

RepLogix Security

Email: RepLogixapp@gmail.com

Website: https://replogix.app