Natty Hatty Signature

Recreational Facilities
Sports Clubs
Parks & Recs

Business Center

Recreational Facilities
Sports Clubs
Parks & Recs

Natty Hatty Customer App

Available on iOS & Android

Parents & Guardians
Players
Coaches

Natty Hatty Signature

Recreational Facilities
Sports Clubs
Parks & Recs

Business Center

Recreational Facilities
Sports Clubs
Parks & Recs

Natty Hatty Customer App

Available on iOS & Android

Parents & Guardians
Players
Coaches
Natty Hatty Signature logo

Back

Security

icon

Natty Hatty — Security Overview

Last Updated: November 15, 2025

At Natty Hatty, protecting the data of Organizations, parents, guardians, coaches, and athletes is a top priority. Youth sports involve sensitive information about families and minors, and we maintain stringent safeguards to keep that data private, secure, and fully compliant.

This page provides a high-level overview of our security practices, infrastructure, policies, and commitments.

Natty Hatty maintains a zero-tolerance policy for activities that endanger minors.

1. Infrastructure & Hosting Security

Amazon Web Services (AWS)

Natty Hatty is hosted on AWS, leveraging:

  • ISO 27001, SOC 1/2/3 certified data centers

  • Secure network architecture

  • Redundant regions & availability zones

  • Encrypted storage (AES-256)

  • Built-in DDoS and firewall controls

Cloudflare Security Layer

All public-facing traffic is protected by Cloudflare:

  • Web Application Firewall (WAF)

  • DDoS mitigation

  • Bot protection

  • TLS termination and certificate management

  • Rate limiting

Together, AWS + Cloudflare ensure high reliability, uptime, and perimeter security.

2. Encryption Standards

Natty Hatty encrypts data:

In Transit:

  • TLS 1.2+ for all public and internal endpoints

  • HSTS enforced

  • Perfect Forward Secrecy (PFS) supported

At Rest:

  • AES-256 block encryption within AWS

  • Encrypted backups

  • Secure key management

No unencrypted traffic is allowed.

3. Identity, Access & Authentication

Internal Access Controls

Natty Hatty team members access systems only under:

  • Strict role-based access control (RBAC)

  • Multi-factor authentication (MFA)

  • Logged and monitored sessions

  • Principle of least privilege

  • Background checks for sensitive roles

User Authentication

Organizations and users authenticate using:

  • Email + password

  • Single-use secure login links (for hosted checkout flows)

  • Tokenized session management

Passwords are never stored in plaintext.

4. Payments & PCI Compliance

Natty Hatty does not store or process raw card data.

Payments are powered by Stripe, a PCI-DSS Level 1 Service Provider.

Natty Hatty is PCI-DSS compliant via SAQ-A using Stripe (PCI Level 1 Service Provider).

All card data is tokenized and transmitted directly to Stripe.

We retain only:

  • Payment IDs

  • Status

  • Metadata

  • Non-sensitive payment results

No card numbers, CVV codes, or ACH routing numbers pass through Natty Hatty servers.

5. Signature Security & Document Integrity

Natty Hatty Signature uses:

  • Immutable audit trails

  • Cryptographically hashed signed documents

  • IP/device logging

  • Version control locking

  • Tamper-evident audit sealing

Once a document is signed, it cannot be altered without invalidating the hash.

Natty Hatty never uses signature data for AI/ML training.

6. Data Protection & Privacy

Privacy frameworks followed:

  • COPPA (Children’s Online Privacy Protection Act)

  • CPRA/CCPA (California privacy requirements)

  • ESIGN / UETA (electronic signature laws)

  • eIDAS (SES level)

  • Do Not Sell/Share compliance (GPC supported)

Natty Hatty does not sell personal data.

Subprocessors:

  • AWS

  • Cloudflare

  • Stripe

  • Google Analytics (non-advertising mode only)

  • Twilio SendGrid

Full list: nattyhatty.com/legal/website-privacy/subprocessors

7. No AI/ML Use on Customer Data

Natty Hatty does not use customer data, signatures, documents, waivers, images, or program information for:

  • Machine learning

  • AI model training

  • Behavioral profiling

  • Advertising

Data is used solely to operate and support the service.

8. Rate Limiting & Anti-Abuse

Natty Hatty monitors and restricts:

  • Automated scraping

  • Excessive requests

  • Credential stuffing attempts

  • Suspicious payment activity

  • Fraud or unauthorized access

  • Abuse of minor-related data

Our system includes dynamic throttling and proactive security rules.

9. Incident Response Program

Natty Hatty maintains a formal Incident Response Policy, including:

  • 24/7 security monitoring

  • Rapid detection & triage

  • Data breach response procedures

  • Customer notification requirements

  • Forensic investigation methods

  • Audit & corrective action processes

High-level policy: nattyhatty.com/security/incident-response

10. Business Continuity & Disaster Recovery

Natty Hatty maintains:

  • Daily encrypted backups

  • Redundant hosting zones

  • Automatic failover for critical components

  • Disaster recovery plan

  • RTO/RPO objectives aligned to industry standards

Critical systems are actively monitored and maintained.

11. Bug Bounty & Responsible Disclosure

Security researchers may report vulnerabilities at:

security@nattyhatty.com

Natty Hatty operates a Responsible Disclosure Program:

  • No legal action for good-faith testing

  • Clear scope definitions

  • Safe harbor protections

  • Acknowledgment for valid findings

Full policy: nattyhatty.com/security/responsible-disclosure

12. Your Responsibilities

Organizations and users must:

  • Use strong passwords

  • Protect login credentials

  • Follow best practices for device safety

  • Ensure their own content follows copyright and privacy laws

  • Use Natty Hatty in compliance with the AUP

  • Protect minor-sensitive data on their end

Natty Hatty provides the infrastructure, but Organizations are responsible for their content and policies.

13. Contact Security Team

For security questions, vulnerability reports, or compliance requests:

security@nattyhatty.comlegal@nattyhatty.com