Security approach
CoachGrind uses technical and organizational safeguards designed to protect coach accounts, play content, playbooks, uploaded diagrams, and program data.
Core safeguards
- Authentication through a dedicated identity provider when hosted auth is enabled.
- Database access limited to service-side code and environment-managed credentials.
- API route authorization checks for authenticated product data.
- Transport security through HTTPS in production hosting environments.
- Operational logging and diagnostics for abuse prevention, reliability, and debugging.
- Access controls intended to limit staff access to information needed for support, operations, and security.
Your responsibilities
- Use a strong password and protect your sign-in method.
- Invite only authorized staff and remove users who no longer need access.
- Avoid entering unnecessary sensitive player, medical, academic, or personal data.
- Review exports before sharing them outside your program.
- Report suspected unauthorized access quickly.
Report a security concern
Send suspected vulnerabilities, account compromise reports, or security concerns to security@coachgrind.com. Please include steps to reproduce, affected URLs, screenshots if safe to share, and your contact information.
No public testing without permission
Do not run destructive tests, denial-of-service tests, social engineering, spam, credential stuffing, or attempts to access data that is not yours. We appreciate responsible reports that protect coaches and programs.
Questions?
Contact support@coachgrind.com for general questions, privacy@coachgrind.com for privacy requests, or security@coachgrind.com for security reports.