Security & Trust
Last updated: July 27, 2026Venues trust us with their bookings, their members' data, and footage of their athletes — many of them minors. We take that seriously. This page describes, in plain terms, how we protect that information. We believe in stating only what is true: everything below is something we actually do and can verify.
Enterprise-grade infrastructure
365 Sports Online runs entirely on Microsoft Azure. That means the physical and cloud infrastructure beneath our platform is operated under Microsoft's independently-audited compliance programs, including SOC 2 Type II, ISO/IEC 27001, and PCI-DSS. We build on top of that certified foundation rather than reinventing it.
To be clear: these are Microsoft Azure's certifications for the infrastructure we run on. 365 Sports Online is not itself a SOC 2- or ISO-certified organization, and we don't claim to be.
Secure payments
All card payments are handled directly by Stripe, a PCI-DSS Level 1 payment provider — the highest level of payment security certification. Your full card number never touches our servers; we store only a transaction reference and the last four digits for your receipts.
How we protect your data
Encryption in transit: every connection uses TLS/HTTPS, enforced with HSTS.
Password protection: passwords are stored using industry-standard salted hashing. We never store or can see your plain-text password.
Access control: role-based permissions with least-privilege access, and server-side checks so users can only reach their own venue's data.
Encrypted secrets: credentials and connected-device passwords are encrypted and kept in secure configuration, never in our source code.
Hardened application: parameterized database access (to prevent injection), strict content-security and framing headers, input validation, and rate limiting to resist abuse.
Consent & audit trail: streaming and media consent is captured digitally, and sensitive actions are recorded in an append-only audit log with timestamp, IP, and device.
Children's privacy (COPPA): accounts for players under 13 require verifiable parental consent, and minors' details are restricted on public and broadcast surfaces.
Backups & recovery
Our databases are backed up automatically with point-in-time restore and geo-redundant backup storage, so data can be recovered even in the event of a regional outage. We test our restore procedures — most recently verified in a documented recovery drill.
Recognized security frameworks
We don't just assert that we're secure — we measure ourselves against established, independent security standards through internal self-assessment:
NIST Cybersecurity Framework (CSF) 2.0 — we organize our security program around the U.S. National Institute of Standards and Technology's framework (Govern, Identify, Protect, Detect, Respond, Recover).
OWASP Application Security Verification Standard (ASVS) — we self-assess our application against this recognized web-application security standard and remediate findings.
OWASP Top 10 — we build and review against the ten most critical web-application security risks.
These are voluntary frameworks we align with and self-assess against — they are not third-party certifications, and we don't represent them as such. We maintain a security roadmap and re-assess as our platform evolves.
Report a vulnerability
If you believe you've found a security vulnerability, we want to hear from you. Please email security@365sports.online with the details and steps to reproduce. We'll acknowledge your report and work with you in good faith to resolve it. Please give us a reasonable opportunity to address the issue before any public disclosure.
Questions
For questions about our security practices — including a summary you can share with your venue's insurer — contact support@365sports.online.