Varsity StackTrust Center

Start your security review.

Every control we operate, the documents your office asks for, and every subprocessor that touches athlete data. In one place, and already prepared.

Overview

Varsity Stack holds supplement information for athletes. For university programs it holds as little about those athletes as the job allows, on a separate database and a separate deployment.

Everything listed here is in place today. Varsity Stack holds no third-party security certification, and nothing on this page should be read as one.

Review readiness

  • HECVAT Full 4.1.6

    Completed, revised August 13, 2026

  • VPAT 2.5Rev / ACR

    Completed, WCAG 2.2 Levels A and AA

  • University DPA

    Prepared, ready to negotiate

  • Governance policies

    Eleven documents, effective August 11, 2026

  • Incident response procedure

    Written and in force

Security & Compliance

Built for institutions that handle sensitive athlete and wellness information, and for the procurement reviews that come with them. Each heading opens to the detail; the controls behind every sentence are in the grid below.

HIPAA

Varsity Stack has executed a Business Associate Agreement with Google Cloud, and runs every workload that may hold protected health information on the Google Cloud services that agreement covers.

The university environment is built to support HIPAA requirements through controls this page documents in detail:

  • Encryption in transit and at rest
  • Role-based, least-privilege access, enforced in the application as well as in the cloud
  • Audit logging and monitoring at both the application and the platform level
  • Secrets held in a managed store, never in code or configuration files
  • Automated database backups with point-in-time recovery
  • Separate development and production projects, with no real health information in development
  • Consumer and catalog workloads kept apart from university athlete workloads
  • Restricted developer and administrative access, on short-lived credentials

HIPAA compliance is a shared responsibility between Varsity Stack, its infrastructure provider and each institution. There is no government HIPAA certification, and we do not claim one.

Google Cloud infrastructure

Production runs on Google Cloud Platform, in projects we own and administer:

  • Cloud SQL for PostgreSQL
  • Cloud Run
  • Google Identity Platform
  • Cloud Storage
  • Secret Manager
  • Cloud Logging and Cloud Audit Logs
  • Cloud Scheduler and Cloud Run Jobs

University athlete information, and anything that may be protected health information, lives in a dedicated team environment separate from the consumer app and the public supplement catalog.

Data segregation

Data is separated by workload into two environments that share no database, credential or identity store.

Consumer and catalog environment

  • Supplement catalog
  • Ingredients
  • Product certifications and certification lots
  • Barcodes
  • Public product research
  • Consumer app accounts and stacks

University environment

  • University staff and athlete accounts
  • Athlete identity mappings
  • Team information
  • Supplement protocols
  • Adherence
  • Wellness check-ins
  • Staff notes
  • Anything else that may be protected health information, depending on the institution’s relationship

Keeping the two apart means a change on the consumer side cannot reach university athlete information, and a reviewer can scope their questions to one environment.

Authentication and access

Authentication is Google Identity Platform. Access is governed by:

  • Owner, admin and member roles, with every permission enforced on the server
  • Application-level authorization on every request, on top of cloud IAM
  • Two-factor authentication on every staff account, which an institution can require of all of its staff
  • Separate sign-in boundaries for consumer and university accounts, enforced in both directions
  • Restricted administrative access, with short-lived credentials for infrastructure administration

Clients never connect to a production database. All traffic goes through authenticated application APIs.

Development and testing

Production athlete health information is never used in development. Development and test environments run in their own Google Cloud projects on synthetic or test data, and hold no role on production.

Incident response

A written procedure covers identifying, investigating, containing, documenting and responding to a security incident, with severity defined against the incident definition in our university DPA.

Institutions are notified of qualifying incidents within the deadlines their agreement and applicable law set.

SOC 2

Varsity Stack has not completed a SOC 2 examination, and does not claim SOC 2 attestation or certification.

Our controls are built against the requirements institutions commonly evaluate, and an independent examination is a step we may take as our institutional customer base and their procurement requirements grow. Until then, the controls on this page are self-described, and the evidence behind them is available on request.

Vendor security review

We support university security and procurement reviews, and provide on request:

  • HECVAT Full 4.1.6, completed and current
  • Accessibility Conformance Report, prepared using VPAT 2.5Rev against WCAG 2.2 Levels A and AA
  • University Data Processing Agreement
  • Architecture and data-flow documentation
  • Business associate agreement details, where applicable
  • Subprocessor list, with each vendor’s role and what it receives
  • Security and privacy policies
  • Backup, restore and business-continuity evidence

Each is listed under Documents with its availability. Security or compliance questions go to support@varsitystack.com.

Documents

Legal

Privacy Policy

Legal

Terms of Use

Privacy

Subprocessor List

Privacy

Retention & Deletion

Security

security.txt (RFC 9116)

Accessibility

Accessibility Statement

Data Security

Application Security

Access Control

Infrastructure

Business Continuity

Privacy

Institutional Scope

Accessibility

Subprocessors

15 services
CompanyPurposeLocationAdditional details
Google CloudCloud hosting, database, authentication and storageUnited Statescloud.google.com/terms/cloud-privacy-notice
SupabaseFormer database and authentication, being retiredUnited Statessupabase.com/privacy
CloudflareContent delivery and firewallUnited States, EEA, and user’s locationcloudflare.com/privacypolicy/
OpenAIReading a scanned product labelUnited Statesopenai.com/policies/privacy-policy
ExpoApp updates and push deliveryUnited Statesexpo.dev/privacy
ResendTransactional emailUnited Statesresend.com/legal/privacy-policy
UpstashRate limitingUnited Statesupstash.com/trust/privacy.pdf
PostHogProduct analyticsUnited Statesposthog.com/privacy
SentryCrash and error reportingUnited Statessentry.io/privacy/
AppleSign in with Apple, distribution, push routingUnited States and user’s locationapple.com/legal/privacy/
GoogleGoogle Sign-In, distribution, push routingUnited States and user’s locationpolicies.google.com/privacy
GitHubSource control and scheduled jobsUnited Statesdocs.github.com/en/site-policy/privacy-policies
NIH Dietary Supplement Label DatabaseProduct identificationUnited Statesdsld.od.nih.gov/
USDA FoodData CentralProduct identification for foodsUnited Statesfdc.nal.usda.gov/
Amazon Product Advertising APIProduct pricing and purchase linksUnited Statesamazon.com/gp/help/customer/display.html?nodeId=468496