Brandlete

Security & Privacy

Athlete Data Deserves Serious Protection.

Brandlete is built around athletes, families, coaches, and organizations, many of them involving minors. Protecting that information isn't an added feature. It's part of how the platform is designed.

From role-based access and server-side authorization to encrypted infrastructure and secure payment processing, Brandlete is built to keep information accessible to the people who should see it, and protected from those who shouldn't.

Protected by design. Controlled by role. Built for sports organizations.

ParentCoachAthleteDirectorOrg Staff
Athlete Record
CoachRequesting own roster
IdentityRelationshipPermission
Access Granted

Access Control

The Right Information. The Right People.

Brandlete's permissions model is built around a user's actual relationship to an athlete. Athletes see their own information. Parents see the children they're formally linked to. Coaches see athletes on their own rosters. Organization staff have permissions based on their responsibilities. Platform administrators have controlled access for support and operations.

Most importantly, these permissions are enforced on Brandlete's servers, not simply by hiding information in the interface. Every request for an athlete record is checked before information is returned. During Brandlete's July 2026 internal security review, these access controls were specifically tested, and no way around them was found.

Request received
User identified
Relationship checked
Permission verified
Information returned
Permission denied

Access is checked, not assumed.

Platform Protection

Protected In Transit. Protected At Rest.

Encrypted connections

Information moving between users and Brandlete is encrypted using HTTPS, with traffic running through Cloudflare.

Private production database

Brandlete's production database is encrypted and is not directly reachable from the public internet. Access is limited to Brandlete's application infrastructure.

Secure authentication

Passwords are stored using one-way protection so Brandlete cannot read or recover a user's actual password. Email verification, rate limiting, and short-lived authentication sessions add additional layers of protection.

Protected uploads

Sensitive image and video upload paths inspect and re-process files before they are made available to other users.

Athlete Privacy

Privacy Matters More When The Athlete Is A Child.

Many athletes using Brandlete are minors, which shapes how information is handled throughout the platform.

Public athlete profiles begin with sensitive information protected. School information, contact details, and academic information are hidden by default, and athletes control which sections of their public profile are shown.

Internal engineering practices are also designed to prevent athlete information from unnecessarily appearing in support tickets, logs, or shared development documents.

Public athlete profile

Highlights & achievementsVisible
School informationHidden by default
Contact detailsHidden by default
Academic informationHidden by default

Athletes control which sections of their profile are shown.

Children's privacy controls continue to evolve as Brandlete prepares for broader rollout.

Payments Powered By Stripe.

When organizations collect registration fees through Brandlete, payment card information is handled directly by Stripe. Card numbers never enter or reside in Brandlete's systems.

Parent
Brandlete Registration
Stripe Secure Payment
Confirmation returned
Card number goes to Stripe only

Brandlete records payment status, not your card number.

Infrastructure

Built On Technology Trusted Around The World.

Brandlete relies on established infrastructure and specialist providers to operate securely and reliably.

Amazon Web ServicesHosting, database, and file storage
CloudflareSecure traffic delivery and protection
StripePayment processing
OpenAIAI-assisted platform features
PostHogProduct usage analytics

Production infrastructure operates within Brandlete-controlled AWS infrastructure in the United States.

Your Information Shouldn't Live Forever By Default.

Brandlete is designed to remove information when it is no longer needed. Organizations can establish retention periods for registration information. Once a program is archived and its configured retention period expires, registration entries, uploaded documents, and associated files can be permanently removed.

Deleting an account is designed to remove that user's information across the platform as one coordinated process rather than leaving disconnected records behind. Expired login sessions are also automatically removed.

Created
Used
Archived
Retention period
Securely deleted

When retention expires, records and files are permanently removed.

Security Doesn't End At Launch.

Before launch, Brandlete conducted an internal security review across the application, infrastructure, permissions model, authentication, and third-party components. That review helped strengthen authentication, session security, platform dependencies, analytics handling, and other areas of the product. Brandlete continues reviewing and improving security as the platform grows.

Internal Security ReviewJuly 2026
ApplicationInfrastructurePermissions modelAuthenticationThird-party components

AI Assists. People Stay In Control.

Brandlete includes AI-assisted features for coaches and administrators, including drafting, summaries, and workflow assistance. AI does not independently communicate with families. A coach or administrator remains responsible for reviewing and initiating communication.

Max drafts
Coach reviews
Coach sends

Built To Protect The People Behind The Platform.

Athlete development requires trust. Brandlete combines thoughtful access controls, encrypted infrastructure, secure authentication, trusted payment processing, and privacy-conscious product design to help organizations protect the athletes and families they serve.

Read the Privacy Policy