Security & Privacy
Athlete Data Deserves Serious Protection.
Brandlete is built around athletes, families, coaches, and organizations, many of them involving minors. Protecting that information isn't an added feature. It's part of how the platform is designed.
From role-based access and server-side authorization to encrypted infrastructure and secure payment processing, Brandlete is built to keep information accessible to the people who should see it, and protected from those who shouldn't.
Protected by design. Controlled by role. Built for sports organizations.
Access Control
The Right Information. The Right People.
Brandlete's permissions model is built around a user's actual relationship to an athlete. Athletes see their own information. Parents see the children they're formally linked to. Coaches see athletes on their own rosters. Organization staff have permissions based on their responsibilities. Platform administrators have controlled access for support and operations.
Most importantly, these permissions are enforced on Brandlete's servers, not simply by hiding information in the interface. Every request for an athlete record is checked before information is returned. During Brandlete's July 2026 internal security review, these access controls were specifically tested, and no way around them was found.
Access is checked, not assumed.
Platform Protection
Protected In Transit. Protected At Rest.
Encrypted connections
Information moving between users and Brandlete is encrypted using HTTPS, with traffic running through Cloudflare.
Private production database
Brandlete's production database is encrypted and is not directly reachable from the public internet. Access is limited to Brandlete's application infrastructure.
Secure authentication
Passwords are stored using one-way protection so Brandlete cannot read or recover a user's actual password. Email verification, rate limiting, and short-lived authentication sessions add additional layers of protection.
Protected uploads
Sensitive image and video upload paths inspect and re-process files before they are made available to other users.
Athlete Privacy
Privacy Matters More When The Athlete Is A Child.
Many athletes using Brandlete are minors, which shapes how information is handled throughout the platform.
Public athlete profiles begin with sensitive information protected. School information, contact details, and academic information are hidden by default, and athletes control which sections of their public profile are shown.
Internal engineering practices are also designed to prevent athlete information from unnecessarily appearing in support tickets, logs, or shared development documents.
Public athlete profile
Athletes control which sections of their profile are shown.
Children's privacy controls continue to evolve as Brandlete prepares for broader rollout.
Payments Powered By Stripe.
When organizations collect registration fees through Brandlete, payment card information is handled directly by Stripe. Card numbers never enter or reside in Brandlete's systems.
Brandlete records payment status, not your card number.
Infrastructure
Built On Technology Trusted Around The World.
Brandlete relies on established infrastructure and specialist providers to operate securely and reliably.
Production infrastructure operates within Brandlete-controlled AWS infrastructure in the United States.
Your Information Shouldn't Live Forever By Default.
Brandlete is designed to remove information when it is no longer needed. Organizations can establish retention periods for registration information. Once a program is archived and its configured retention period expires, registration entries, uploaded documents, and associated files can be permanently removed.
Deleting an account is designed to remove that user's information across the platform as one coordinated process rather than leaving disconnected records behind. Expired login sessions are also automatically removed.
When retention expires, records and files are permanently removed.
Security Doesn't End At Launch.
Before launch, Brandlete conducted an internal security review across the application, infrastructure, permissions model, authentication, and third-party components. That review helped strengthen authentication, session security, platform dependencies, analytics handling, and other areas of the product. Brandlete continues reviewing and improving security as the platform grows.
AI Assists. People Stay In Control.
Brandlete includes AI-assisted features for coaches and administrators, including drafting, summaries, and workflow assistance. AI does not independently communicate with families. A coach or administrator remains responsible for reviewing and initiating communication.
Built To Protect The People Behind The Platform.
Athlete development requires trust. Brandlete combines thoughtful access controls, encrypted infrastructure, secure authentication, trusted payment processing, and privacy-conscious product design to help organizations protect the athletes and families they serve.