Back to Compliance

RepLogix Risk Assessment

Effective Date: August 8, 2026

This Risk Assessment documents the identified risks to RepLogix's information assets, their likelihood and impact, and the treatment plans to mitigate them. It supports our commitment to proactive security management and our roadmap toward ISO 27001 and SOC 2 Type II.

1. Purpose and Methodology

This risk assessment identifies threats, vulnerabilities, and risks to RepLogix's information assets. Risks are evaluated based on likelihood and impact, then assigned a treatment plan. The assessment is conducted at least annually and when significant changes occur.

Risk rating: Low (1–4) · Medium (5–9) · High (10–16) · Critical (17–25). Score = Likelihood (1–5) × Impact (1–5).

2. Asset Inventory Summary

AssetClassificationOwner
RepLogix Application (web + mobile)ConfidentialDevelopment Team
Production DatabaseConfidentialBase44 / RepLogix
Authentication SystemRestrictedBase44
API Keys & SecretsRestrictedSecurity Lead
Customer Data (athlete, coach, billing)ConfidentialRepLogix
Source CodeInternalDevelopment Team
BackupsConfidentialBase44
Email/SMS Notification LogsInternalRepLogix

3. Risk Register

RiskLikelihoodImpactScoreTreatment
Unauthorized access to customer data2510 (High)RBAC, MFA, encryption, access reviews
Data breach via compromised credentials3515 (High)MFA, password policy, monitoring
Third-party/subprocessor breach248 (Medium)Vendor due diligence, contracts
Application vulnerability exploitation248 (Medium)Secure coding, code review, testing
Insider threat (malicious or accidental)155 (Medium)Least privilege, access reviews, training
Data loss due to system failure248 (Medium)Backups, BCDR plan, restoration testing
Phishing attack on personnel339 (Medium)Security awareness training, MFA
Denial of service / availability disruption236 (Medium)Infrastructure redundancy, monitoring
Inadequate vulnerability patching236 (Medium)Dependency monitoring, patch schedule
FERPA/COPPA compliance violation155 (Medium)Data minimization, consent workflows, policies
Loss of encryption keys / secrets155 (Medium)Secret management, access controls

4. Risk Treatment Summary

Based on the risk register, the following treatment actions are prioritized:

  • High Priority: Enforce MFA for all privileged accounts, strengthen credential monitoring, conduct phishing simulations
  • Medium Priority: Complete vendor due diligence reviews, implement restoration testing, enhance vulnerability scanning
  • Ongoing: Maintain access reviews, security awareness training, and policy updates

5. Residual Risk

After treatment, residual risks are accepted by management. No risks are rated Critical after treatment. Residual risk is reviewed at the next assessment cycle or when significant changes occur.

6. Assessment Review

This risk assessment is reviewed and updated at least annually, after significant incidents, or when major changes to systems, data, or organizational structure occur.

7. Contact

For questions about this risk assessment, contact:

RepLogix Security

Email: RepLogixapp@gmail.com