Back
Security
Natty Hatty — Security Overview
Last Updated: November 15, 2025
At Natty Hatty, protecting the data of Organizations, parents, guardians, coaches, and athletes is a top priority. Youth sports involve sensitive information about families and minors, and we maintain stringent safeguards to keep that data private, secure, and fully compliant.
This page provides a high-level overview of our security practices, infrastructure, policies, and commitments.
Natty Hatty maintains a zero-tolerance policy for activities that endanger minors.
1. Infrastructure & Hosting Security
Amazon Web Services (AWS)
Natty Hatty is hosted on AWS, leveraging:
ISO 27001, SOC 1/2/3 certified data centers
Secure network architecture
Redundant regions & availability zones
Encrypted storage (AES-256)
Built-in DDoS and firewall controls
Cloudflare Security Layer
All public-facing traffic is protected by Cloudflare:
Web Application Firewall (WAF)
DDoS mitigation
Bot protection
TLS termination and certificate management
Rate limiting
Together, AWS + Cloudflare ensure high reliability, uptime, and perimeter security.
2. Encryption Standards
Natty Hatty encrypts data:
In Transit:
TLS 1.2+ for all public and internal endpoints
HSTS enforced
Perfect Forward Secrecy (PFS) supported
At Rest:
AES-256 block encryption within AWS
Encrypted backups
Secure key management
No unencrypted traffic is allowed.
3. Identity, Access & Authentication
Internal Access Controls
Natty Hatty team members access systems only under:
Strict role-based access control (RBAC)
Multi-factor authentication (MFA)
Logged and monitored sessions
Principle of least privilege
Background checks for sensitive roles
User Authentication
Organizations and users authenticate using:
Email + password
Single-use secure login links (for hosted checkout flows)
Tokenized session management
Passwords are never stored in plaintext.
4. Payments & PCI Compliance
Natty Hatty does not store or process raw card data.
Payments are powered by Stripe, a PCI-DSS Level 1 Service Provider.
Natty Hatty is PCI-DSS compliant via SAQ-A using Stripe (PCI Level 1 Service Provider).
All card data is tokenized and transmitted directly to Stripe.
We retain only:
Payment IDs
Status
Metadata
Non-sensitive payment results
No card numbers, CVV codes, or ACH routing numbers pass through Natty Hatty servers.
5. Signature Security & Document Integrity
Natty Hatty Signature uses:
Immutable audit trails
Cryptographically hashed signed documents
IP/device logging
Version control locking
Tamper-evident audit sealing
Once a document is signed, it cannot be altered without invalidating the hash.
Natty Hatty never uses signature data for AI/ML training.
6. Data Protection & Privacy
Privacy frameworks followed:
COPPA (Children’s Online Privacy Protection Act)
CPRA/CCPA (California privacy requirements)
ESIGN / UETA (electronic signature laws)
eIDAS (SES level)
Do Not Sell/Share compliance (GPC supported)
Natty Hatty does not sell personal data.
Subprocessors:
AWS
Cloudflare
Stripe
Google Analytics (non-advertising mode only)
Twilio SendGrid
Full list: nattyhatty.com/legal/website-privacy/subprocessors
7. No AI/ML Use on Customer Data
Natty Hatty does not use customer data, signatures, documents, waivers, images, or program information for:
Machine learning
AI model training
Behavioral profiling
Advertising
Data is used solely to operate and support the service.
8. Rate Limiting & Anti-Abuse
Natty Hatty monitors and restricts:
Automated scraping
Excessive requests
Credential stuffing attempts
Suspicious payment activity
Fraud or unauthorized access
Abuse of minor-related data
Our system includes dynamic throttling and proactive security rules.
9. Incident Response Program
Natty Hatty maintains a formal Incident Response Policy, including:
24/7 security monitoring
Rapid detection & triage
Data breach response procedures
Customer notification requirements
Forensic investigation methods
Audit & corrective action processes
High-level policy: nattyhatty.com/security/incident-response
10. Business Continuity & Disaster Recovery
Natty Hatty maintains:
Daily encrypted backups
Redundant hosting zones
Automatic failover for critical components
Disaster recovery plan
RTO/RPO objectives aligned to industry standards
Critical systems are actively monitored and maintained.
11. Bug Bounty & Responsible Disclosure
Security researchers may report vulnerabilities at:
Natty Hatty operates a Responsible Disclosure Program:
No legal action for good-faith testing
Clear scope definitions
Safe harbor protections
Acknowledgment for valid findings
Full policy: nattyhatty.com/security/responsible-disclosure
12. Your Responsibilities
Organizations and users must:
Use strong passwords
Protect login credentials
Follow best practices for device safety
Ensure their own content follows copyright and privacy laws
Use Natty Hatty in compliance with the AUP
Protect minor-sensitive data on their end
Natty Hatty provides the infrastructure, but Organizations are responsible for their content and policies.
13. Contact Security Team
For security questions, vulnerability reports, or compliance requests: