Start your security review.
Every control we operate, the documents your office asks for, and every subprocessor that touches athlete data. In one place, and already prepared.
Overview
Varsity Stack holds supplement information for athletes. For university programs it holds as little about those athletes as the job allows, on a separate database and a separate deployment.
Everything listed here is in place today. Varsity Stack holds no third-party security certification, and nothing on this page should be read as one.
Review readiness
- checkmark_circle_fill
HECVAT Full 4.1.6
Completed, revised August 13, 2026
- checkmark_circle_fill
VPAT 2.5Rev / ACR
Completed, WCAG 2.2 Levels A and AA
- checkmark_circle_fill
University DPA
Prepared, ready to negotiate
- checkmark_circle_fill
Governance policies
Eleven documents, effective August 11, 2026
- checkmark_circle_fill
Incident response procedure
Written and in force
Security & Compliance
Built for institutions that handle sensitive athlete and wellness information, and for the procurement reviews that come with them. Each heading opens to the detail; the controls behind every sentence are in the grid below.
chevron_rightHIPAA
Varsity Stack has executed a Business Associate Agreement with Google Cloud, and runs every workload that may hold protected health information on the Google Cloud services that agreement covers.
The university environment is built to support HIPAA requirements through controls this page documents in detail:
- checkmark_circle_fillEncryption in transit and at rest
- checkmark_circle_fillRole-based, least-privilege access, enforced in the application as well as in the cloud
- checkmark_circle_fillAudit logging and monitoring at both the application and the platform level
- checkmark_circle_fillSecrets held in a managed store, never in code or configuration files
- checkmark_circle_fillAutomated database backups with point-in-time recovery
- checkmark_circle_fillSeparate development and production projects, with no real health information in development
- checkmark_circle_fillConsumer and catalog workloads kept apart from university athlete workloads
- checkmark_circle_fillRestricted developer and administrative access, on short-lived credentials
HIPAA compliance is a shared responsibility between Varsity Stack, its infrastructure provider and each institution. There is no government HIPAA certification, and we do not claim one.
chevron_rightGoogle Cloud infrastructure
Production runs on Google Cloud Platform, in projects we own and administer:
- checkmark_circle_fillCloud SQL for PostgreSQL
- checkmark_circle_fillCloud Run
- checkmark_circle_fillGoogle Identity Platform
- checkmark_circle_fillCloud Storage
- checkmark_circle_fillSecret Manager
- checkmark_circle_fillCloud Logging and Cloud Audit Logs
- checkmark_circle_fillCloud Scheduler and Cloud Run Jobs
University athlete information, and anything that may be protected health information, lives in a dedicated team environment separate from the consumer app and the public supplement catalog.
chevron_rightData segregation
Data is separated by workload into two environments that share no database, credential or identity store.
Consumer and catalog environment
- Supplement catalog
- Ingredients
- Product certifications and certification lots
- Barcodes
- Public product research
- Consumer app accounts and stacks
University environment
- University staff and athlete accounts
- Athlete identity mappings
- Team information
- Supplement protocols
- Adherence
- Wellness check-ins
- Staff notes
- Anything else that may be protected health information, depending on the institution’s relationship
Keeping the two apart means a change on the consumer side cannot reach university athlete information, and a reviewer can scope their questions to one environment.
chevron_rightAuthentication and access
Authentication is Google Identity Platform. Access is governed by:
- checkmark_circle_fillOwner, admin and member roles, with every permission enforced on the server
- checkmark_circle_fillApplication-level authorization on every request, on top of cloud IAM
- checkmark_circle_fillTwo-factor authentication on every staff account, which an institution can require of all of its staff
- checkmark_circle_fillSeparate sign-in boundaries for consumer and university accounts, enforced in both directions
- checkmark_circle_fillRestricted administrative access, with short-lived credentials for infrastructure administration
Clients never connect to a production database. All traffic goes through authenticated application APIs.
chevron_rightDevelopment and testing
Production athlete health information is never used in development. Development and test environments run in their own Google Cloud projects on synthetic or test data, and hold no role on production.
chevron_rightIncident response
A written procedure covers identifying, investigating, containing, documenting and responding to a security incident, with severity defined against the incident definition in our university DPA.
Institutions are notified of qualifying incidents within the deadlines their agreement and applicable law set.
chevron_rightSOC 2
Varsity Stack has not completed a SOC 2 examination, and does not claim SOC 2 attestation or certification.
Our controls are built against the requirements institutions commonly evaluate, and an independent examination is a step we may take as our institutional customer base and their procurement requirements grow. Until then, the controls on this page are self-described, and the evidence behind them is available on request.
chevron_rightVendor security review
We support university security and procurement reviews, and provide on request:
- checkmark_circle_fillHECVAT Full 4.1.6, completed and current
- checkmark_circle_fillAccessibility Conformance Report, prepared using VPAT 2.5Rev against WCAG 2.2 Levels A and AA
- checkmark_circle_fillUniversity Data Processing Agreement
- checkmark_circle_fillArchitecture and data-flow documentation
- checkmark_circle_fillBusiness associate agreement details, where applicable
- checkmark_circle_fillSubprocessor list, with each vendor’s role and what it receives
- checkmark_circle_fillSecurity and privacy policies
- checkmark_circle_fillBackup, restore and business-continuity evidence
Each is listed under Documents with its availability. Security or compliance questions go to support@varsitystack.com.
Documents
Data Security
Application Security
Access Control
Infrastructure
Business Continuity
Privacy
Institutional Scope
Accessibility
Subprocessors
15 services| Company | Purpose | Location | Additional details |
|---|---|---|---|
| Cloud hosting, database, authentication and storage | United States | cloud.google.com/terms/cloud-privacy-notice | |
| Former database and authentication, being retired | United States | supabase.com/privacy | |
| Content delivery and firewall | United States, EEA, and user’s location | cloudflare.com/privacypolicy/ | |
| Reading a scanned product label | United States | openai.com/policies/privacy-policy | |
| App updates and push delivery | United States | expo.dev/privacy | |
| Transactional email | United States | resend.com/legal/privacy-policy | |
| Rate limiting | United States | upstash.com/trust/privacy.pdf | |
| Product analytics | United States | posthog.com/privacy | |
| Crash and error reporting | United States | sentry.io/privacy/ | |
| Sign in with Apple, distribution, push routing | United States and user’s location | apple.com/legal/privacy/ | |
| Google Sign-In, distribution, push routing | United States and user’s location | policies.google.com/privacy | |
| Source control and scheduled jobs | United States | docs.github.com/en/site-policy/privacy-policies | |
| Product identification | United States | dsld.od.nih.gov/ | |
| Product identification for foods | United States | fdc.nal.usda.gov/ | |
| Product pricing and purchase links | United States | amazon.com/gp/help/customer/display.html?nodeId=468496 |
