Natty Hatty Signature

Recreational Facilities
Sports Clubs
Parks & Recs

Business Center

Recreational Facilities
Sports Clubs
Parks & Recs

Natty Hatty Customer App

Available on iOS & Android

Parents & Guardians
Players
Coaches

Natty Hatty Signature

Recreational Facilities
Sports Clubs
Parks & Recs

Business Center

Recreational Facilities
Sports Clubs
Parks & Recs

Natty Hatty Customer App

Available on iOS & Android

Parents & Guardians
Players
Coaches
Natty Hatty Signature logo

Back

Security

icon

Natty Hatty Security Overview

Last Updated: November 15, 2025

Version: v1.0

Natty Hatty is built for youth sports organizations, families, and athletes — and we take their security, privacy, and data protection extremely seriously. This Security Overview outlines how we safeguard data across our platform.

1. Platform Security Principles

We follow industry-leading security practices grounded in four principles:

  1. Confidentiality — Your data is encrypted at rest and in transit.

  2. Integrity — Signed documents, audit trails, and payment records cannot be altered or tampered with.

  3. Availability — The platform is hosted on scalable, high-reliability AWS infrastructure.

  4. Transparency — No AI/ML models are trained on customer data. Ever.

2. Encryption Standards

2.1 Data-In-Transit Encryption

All data transmitted between your device and Natty Hatty services is encrypted using:

  • TLS 1.2+

  • AES-256 GCM cipher suites

  • HSTS (HTTP Strict Transport Security)

  • Perfect Forward Secrecy (PFS) enabled

This ensures that data cannot be intercepted or accessed during transmission.

2.2 Data-At-Rest Encryption

All data stored within Natty Hatty is encrypted using:

  • AES-256 encryption at rest

  • Encrypted RDS storage for databases

  • Encrypted S3 buckets for files (documents, waivers, signed PDFs, audit logs)

  • Encryption keys are managed securely through AWS Key Management Service (KMS).

3. Infrastructure & Hosting (AWS Overview)

Natty Hatty is hosted on Amazon Web Services (AWS) — the industry standard for secure, compliant, and scalable cloud infrastructure.

Our deployments use:

  • AWS EC2 for compute

  • AWS RDS (PostgreSQL) for databases

  • AWS S3 for document storage

  • AWS CloudFront for CDN distribution

  • AWS Lambda for background tasks

  • AWS KMS for key management

  • AWS WAF & Shield for DDoS protection

  • AWS CloudWatch for monitoring and logging

AWS provides compliance with:

  • SOC 1 / SOC 2

  • ISO 27001

  • PCI-DSS

  • FedRAMP

  • CSA STAR

Natty Hatty inherits infrastructure-level compliance from AWS while following its own application-level security controls.

4. Document Security & Signature Integrity

Natty Hatty Signature (e-signature system) includes:

  • Tamper-Proof Audit Trails

    • IP address

    • Device ID

    • Browser fingerprint

    • Timestamp (UTC)

    • Signature hash

    • Signing sequence logs

Once a document is signed:

  • A cryptographic hash is generated

  • The PDF is locked and immutable

  • Any modification invalidates the hash

This ensures ESIGN, UETA, and eIDAS compliance.

5. Data Retention & Storage Policies

We maintain strict retention schedules for documents, signatures, and audit logs.

5.1 Waivers & Signed Documents

Stored for 7 years (standard liability window for youth sports). After expiration, documents are securely deleted from storage.

5.2 Audit Trails

Retained for 7 years, even if the original document is deleted. Cannot be edited or removed by users.

5.3 Account Data

Organization accounts: retained while active. Personal data: removed upon verified deletion request (subject to legal exceptions).

5.4 Payment Data

Natty Hatty does not store or process card data. Stripe manages all sensitive payment information.

6. “No AI/ML Use” Commitment

Natty Hatty does NOT:

  • Train any AI or machine learning models on your data

  • Use your waivers, documents, or player information to build predictive systems

  • Sell or share your data with any AI companies

  • Use uploaded data for product training or automated decision-making

All customer data is used solely for product functionality and compliance.

7. Incident Response Policy

Natty Hatty maintains a formal Incident Response Plan (IRP) to quickly detect, respond to, and resolve security incidents.

7.1 Detection

  • Automated monitoring (CloudWatch, WAF)

  • Log analysis

  • Intrusion alerts

  • Escalation triggers

7.2 Containment

  • Immediate isolation of affected systems

  • Revocation of compromised keys

  • Forced logout of affected accounts

7.3 Investigation

Root-cause analysis. Log review. Forensic evidence capture.

7.4 Notification

If a breach involving personal or sensitive data occurs:

  • Impacted users will be notified promptly

  • We comply with applicable state, federal, and international laws

  • Law enforcement may be contacted when required

7.5 Remediation

  • Patch deployment

  • Security improvements

  • Policy revisions

  • Post-incident reporting

8. Penetration Testing

Natty Hatty conducts periodic:

  • Internal security tests

  • External penetration tests (3rd-party)

  • OWASP Top 10 vulnerability testing

Critical vulnerabilities are remediated with priority.

9. Bug Bounty Program

We are preparing a formal program. For now, responsible disclosures may be submitted to:

security@nattyhatty.com

Researchers are asked not to perform testing that may:

  • Affect platform availability

  • Access or modify real customer data

  • Disrupt youth sports operations

A standard responsible disclosure policy will be published soon.

10. Access Controls & Authentication

10.1 Role-Based Access Control (RBAC)

Permissions vary for:

  • Owners

  • Coaches

  • Staff

  • Guardians

  • Athletes

Users only see what they are authorized to see.

10.2 Multi-Factor Authentication (MFA)

Supported for organization owners and admins.

10.3 Secure Session Management

  • Short-lived tokens

  • Auto-expiring sessions

  • Device-based access monitoring

11. Monitoring & Logging

Natty Hatty uses:

  • Real-time API traffic monitoring

  • Automated anomaly detection

  • Audit logs for admin actions

  • IP & device-level session tracking

  • Suspicious patterns trigger alerts.

12. Data Isolation & Internal Access Controls

Internal access is strictly limited:

  • Zero standing privileges

  • Least-privilege access

  • Logged and audited personnel access

  • Separation between production and development environments

13. Contact Us

For security concerns, disclosures, or inquiries:

security@nattyhatty.comlegal@nattyhatty.com