Effective Date: August 8, 2026
This Risk Assessment documents the identified risks to RepLogix's information assets, their likelihood and impact, and the treatment plans to mitigate them. It supports our commitment to proactive security management and our roadmap toward ISO 27001 and SOC 2 Type II.
This risk assessment identifies threats, vulnerabilities, and risks to RepLogix's information assets. Risks are evaluated based on likelihood and impact, then assigned a treatment plan. The assessment is conducted at least annually and when significant changes occur.
Risk rating: Low (1–4) · Medium (5–9) · High (10–16) · Critical (17–25). Score = Likelihood (1–5) × Impact (1–5).
| Asset | Classification | Owner |
|---|---|---|
| RepLogix Application (web + mobile) | Confidential | Development Team |
| Production Database | Confidential | Base44 / RepLogix |
| Authentication System | Restricted | Base44 |
| API Keys & Secrets | Restricted | Security Lead |
| Customer Data (athlete, coach, billing) | Confidential | RepLogix |
| Source Code | Internal | Development Team |
| Backups | Confidential | Base44 |
| Email/SMS Notification Logs | Internal | RepLogix |
| Risk | Likelihood | Impact | Score | Treatment |
|---|---|---|---|---|
| Unauthorized access to customer data | 2 | 5 | 10 (High) | RBAC, MFA, encryption, access reviews |
| Data breach via compromised credentials | 3 | 5 | 15 (High) | MFA, password policy, monitoring |
| Third-party/subprocessor breach | 2 | 4 | 8 (Medium) | Vendor due diligence, contracts |
| Application vulnerability exploitation | 2 | 4 | 8 (Medium) | Secure coding, code review, testing |
| Insider threat (malicious or accidental) | 1 | 5 | 5 (Medium) | Least privilege, access reviews, training |
| Data loss due to system failure | 2 | 4 | 8 (Medium) | Backups, BCDR plan, restoration testing |
| Phishing attack on personnel | 3 | 3 | 9 (Medium) | Security awareness training, MFA |
| Denial of service / availability disruption | 2 | 3 | 6 (Medium) | Infrastructure redundancy, monitoring |
| Inadequate vulnerability patching | 2 | 3 | 6 (Medium) | Dependency monitoring, patch schedule |
| FERPA/COPPA compliance violation | 1 | 5 | 5 (Medium) | Data minimization, consent workflows, policies |
| Loss of encryption keys / secrets | 1 | 5 | 5 (Medium) | Secret management, access controls |
Based on the risk register, the following treatment actions are prioritized:
After treatment, residual risks are accepted by management. No risks are rated Critical after treatment. Residual risk is reviewed at the next assessment cycle or when significant changes occur.
This risk assessment is reviewed and updated at least annually, after significant incidents, or when major changes to systems, data, or organizational structure occur.
For questions about this risk assessment, contact:
RepLogix Security
Email: RepLogixapp@gmail.com