Back
Security
Natty Hatty Security Overview
Last Updated: November 15, 2025
Version: v1.0
Natty Hatty is built for youth sports organizations, families, and athletes — and we take their security, privacy, and data protection extremely seriously. This Security Overview outlines how we safeguard data across our platform.
1. Platform Security Principles
We follow industry-leading security practices grounded in four principles:
Confidentiality — Your data is encrypted at rest and in transit.
Integrity — Signed documents, audit trails, and payment records cannot be altered or tampered with.
Availability — The platform is hosted on scalable, high-reliability AWS infrastructure.
Transparency — No AI/ML models are trained on customer data. Ever.
2. Encryption Standards
2.1 Data-In-Transit Encryption
All data transmitted between your device and Natty Hatty services is encrypted using:
TLS 1.2+
AES-256 GCM cipher suites
HSTS (HTTP Strict Transport Security)
Perfect Forward Secrecy (PFS) enabled
This ensures that data cannot be intercepted or accessed during transmission.
2.2 Data-At-Rest Encryption
All data stored within Natty Hatty is encrypted using:
AES-256 encryption at rest
Encrypted RDS storage for databases
Encrypted S3 buckets for files (documents, waivers, signed PDFs, audit logs)
Encryption keys are managed securely through AWS Key Management Service (KMS).
3. Infrastructure & Hosting (AWS Overview)
Natty Hatty is hosted on Amazon Web Services (AWS) — the industry standard for secure, compliant, and scalable cloud infrastructure.
Our deployments use:
AWS EC2 for compute
AWS RDS (PostgreSQL) for databases
AWS S3 for document storage
AWS CloudFront for CDN distribution
AWS Lambda for background tasks
AWS KMS for key management
AWS WAF & Shield for DDoS protection
AWS CloudWatch for monitoring and logging
AWS provides compliance with:
SOC 1 / SOC 2
ISO 27001
PCI-DSS
FedRAMP
CSA STAR
Natty Hatty inherits infrastructure-level compliance from AWS while following its own application-level security controls.
4. Document Security & Signature Integrity
Natty Hatty Signature (e-signature system) includes:
Tamper-Proof Audit Trails
IP address
Device ID
Browser fingerprint
Timestamp (UTC)
Signature hash
Signing sequence logs
Once a document is signed:
A cryptographic hash is generated
The PDF is locked and immutable
Any modification invalidates the hash
This ensures ESIGN, UETA, and eIDAS compliance.
5. Data Retention & Storage Policies
We maintain strict retention schedules for documents, signatures, and audit logs.
5.1 Waivers & Signed Documents
Stored for 7 years (standard liability window for youth sports). After expiration, documents are securely deleted from storage.
5.2 Audit Trails
Retained for 7 years, even if the original document is deleted. Cannot be edited or removed by users.
5.3 Account Data
Organization accounts: retained while active. Personal data: removed upon verified deletion request (subject to legal exceptions).
5.4 Payment Data
Natty Hatty does not store or process card data. Stripe manages all sensitive payment information.
6. “No AI/ML Use” Commitment
Natty Hatty does NOT:
Train any AI or machine learning models on your data
Use your waivers, documents, or player information to build predictive systems
Sell or share your data with any AI companies
Use uploaded data for product training or automated decision-making
All customer data is used solely for product functionality and compliance.
7. Incident Response Policy
Natty Hatty maintains a formal Incident Response Plan (IRP) to quickly detect, respond to, and resolve security incidents.
7.1 Detection
Automated monitoring (CloudWatch, WAF)
Log analysis
Intrusion alerts
Escalation triggers
7.2 Containment
Immediate isolation of affected systems
Revocation of compromised keys
Forced logout of affected accounts
7.3 Investigation
Root-cause analysis. Log review. Forensic evidence capture.
7.4 Notification
If a breach involving personal or sensitive data occurs:
Impacted users will be notified promptly
We comply with applicable state, federal, and international laws
Law enforcement may be contacted when required
7.5 Remediation
Patch deployment
Security improvements
Policy revisions
Post-incident reporting
8. Penetration Testing
Natty Hatty conducts periodic:
Internal security tests
External penetration tests (3rd-party)
OWASP Top 10 vulnerability testing
Critical vulnerabilities are remediated with priority.
9. Bug Bounty Program
We are preparing a formal program. For now, responsible disclosures may be submitted to:
Researchers are asked not to perform testing that may:
Affect platform availability
Access or modify real customer data
Disrupt youth sports operations
A standard responsible disclosure policy will be published soon.
10. Access Controls & Authentication
10.1 Role-Based Access Control (RBAC)
Permissions vary for:
Owners
Coaches
Staff
Guardians
Athletes
Users only see what they are authorized to see.
10.2 Multi-Factor Authentication (MFA)
Supported for organization owners and admins.
10.3 Secure Session Management
Short-lived tokens
Auto-expiring sessions
Device-based access monitoring
11. Monitoring & Logging
Natty Hatty uses:
Real-time API traffic monitoring
Automated anomaly detection
Audit logs for admin actions
IP & device-level session tracking
Suspicious patterns trigger alerts.
12. Data Isolation & Internal Access Controls
Internal access is strictly limited:
Zero standing privileges
Least-privilege access
Logged and audited personnel access
Separation between production and development environments
13. Contact Us
For security concerns, disclosures, or inquiries: