Security & Privacy at Red Card

Red Card Athletics serves 110+ athletic departments and 45,000+ athletes. Athletic staff, compliance officers, and university IT all have a stake in how we handle that data. This page explains how, and tells you how to get what your security review needs.

Security questions or documentation requests: security@goredcard.com

Where your data lives

Red Card's architecture separates payment processing from application services. The data that carries the most risk is held by providers whose core business is secure payments, not by Red Card.

DataHeld byCompliance posture
Application and directory data: name, team affiliation, university email, phoneRed Card, hosted on Amazon Web Services in the United StatesDocumented in our HECVAT and a System Security Plan against NIST SP 800-171; AWS maintains SOC 2 and related attestations for the hosting environment
ACH and bank account informationAeropayAnnual SOC 2 Type II examination
Prepaid debit card processingTern CommercePCI DSS v4.0.1 Attestation of Compliance (SAQ D, Service Provider), assessed by a Qualified Security Assessor

Red Card's platform is not designed to process, store, or transmit credit card information. Card numbers are entered and displayed only within a secure frame hosted by our issuing partner. Institutional data is not transferred outside the United States at any point during collection, processing, or storage.

We're glad to walk your security team through the full data flow. Contact us and we'll set it up.

How we protect it

Encryption. Data is encrypted in transit using TLS and at rest across the production database, file storage, and all server volumes using AWS Key Management Service, with encryption by default enabled so new storage is encrypted on creation. Key use is restricted by policy and logged. Passwords are stored as one-way hashes and are never held in recoverable form.

Least-privilege access. Access to production systems is role-based and granted only where a business responsibility requires it. Administrative access requires multi-factor authentication and is audit-logged. Access is revoked promptly on separation and entitlements are reviewed.

Continuous monitoring. A third-party managed detection and response service provides 24x7x365 intrusion monitoring across endpoints and servers, with cloud-layer threat detection in AWS. Infrastructure changes are logged through AWS CloudTrail, and configurations are continuously assessed against the CIS AWS Foundations Benchmark.

Vulnerability management. Installed packages on every server are continuously assessed through authenticated scanning, application dependencies are checked on every code change and against newly published advisories, and fleet-wide patch compliance is scanned daily. Remediation follows severity-based timelines defined in our Patch Management Policy.

Single sign-on. Red Card supports SAML 2.0 web SSO, federated through Amazon Cognito. Institutions can federate their existing identity provider; Shibboleth and Microsoft Entra ID integrations are running in production today, and reference institutions and configuration details are available on request. Where an institution does not federate, admin access uses Red Card's own credential system with enforced MFA and role-based permissions. Red Card is not a registered Service Provider in the InCommon or eduGAIN federations; we federate directly with institutions, and will evaluate SP registration where an institution's process requires it.

Framework alignment. Our security program is documented against NIST SP 800-171 in a maintained System Security Plan, supported by named-owner policies on an annual review cycle.

Backups and recovery. The production database, file storage, and server volumes are backed up daily through AWS Backup into retention-locked vaults, encrypted at rest and in transit, with recovery points copied to a second United States region. Restore procedures are tested, and all backup data remains within the United States.

Incident response. We maintain a documented incident response plan covering identification, containment, investigation, recovery, customer communication, and post-incident review. In the event of a breach involving personal data, we notify the affected institution without undue delay, consistent with our incident response plan and contractual commitments.

Cyber-risk insurance. Red Card carries cyber-risk insurance covering service outages, data loss, and related events. Coverage details are available to institutions on request.

Change management. We maintain a documented change control process covering authorization, impact analysis, and testing, with releases gated on the remediation of critical findings, and a patch management policy governing how critical patches are applied and how risk is mitigated in the interim.

Privacy

We collect the minimum we need to run the service: name, team affiliation, university email, phone number (optional), and limited device information.

We don't collect what we don't need. Red Card does not collect demographic information: no race, ethnicity, or gender. We do not capture biometric or behaviometric data. The Red Card athlete app and admin dashboard contain no advertising or tracking pixels. (Our public marketing site uses Google Analytics and social media features, described in our Privacy Policy; the platform itself does not.)

Red Card does not sell customer data.

Your institution owns its data and remains the system of record for its users. Requests for access, correction, or deletion are coordinated through the institution.

FERPA. Red Card processes FERPA-related data as a school official under the institution's direct control, and handles it accordingly.

Full detail: Privacy Policy

Accessibility

Red Card has adopted WCAG 2.2 Level AA as our technical standard of conformance, and new development is built to it. We maintain an Accessibility Statement and an accessibility roadmap recording identified gaps and their remediation status. Our VPAT and roadmap are available on request.

Documentation for your security review

We maintain and will provide, on request:

  • HECVAT (Full)
  • System Security Plan against NIST SP 800-171, including data flow diagrams
  • Disaster Recovery Plan
  • Data Privacy, Data Retention, Change Control, Patch Management, and supporting security policies
  • Subprocessor register, scoped by product
  • Payment processor attestations (Aeropay SOC 2, Tern Commerce PCI DSS)
  • VPAT and accessibility documentation
  • AI Component Disclosure and AI risk register
  • Third-party security assessment results

Common questions

Do you have a SOC 2 report?

Red Card does not hold its own SOC 2 report. Our platform is hosted on AWS, which maintains SOC 2 for the hosting environment, and the regulated financial data in our ecosystem is held by Aeropay (SOC 2) and Tern Commerce (PCI DSS) rather than by Red Card. We can provide those attestations along with our HECVAT, System Security Plan, and architecture documentation to support your review. If your process requires something specific, reach out early and we'll work through it with your team.

Do you have a HECVAT?

Yes, current and verified against our production environment. Request it above.

How do we report a security concern?

security@goredcard.com

Last updated: August 12, 2026