Security

Bank-grade encryption. Built in from day one.

Your season-ticket records contain dollar amounts, seat numbers, and counterparty data. We treat them the way a bank treats a brokerage statement.

Encryption

Encryption at rest and in transit.

Database storage and backups are encrypted by Supabase using industry-standard AES-256 ciphers. Every connection between your browser, our servers, and our subprocessors uses TLS 1.3.

Authentication

Clerk-backed auth · MFA available.

Sign in with email, Google, or Apple. Two-factor authentication available on every account via authenticator apps. Session tokens rotated per industry standard.

Audit trail
Coming soon

Every change, logged and timestamped.

Game reassignments, fee adjustments, sale recordings, statement signatures — all timestamped and attributable to the user who made the change. Useful for co-owner disputes and audit prep.

Privacy

Your data stays yours. Always.

We don't sell data. We don't share with brokers. We don't train AI models on your records. Export everything to CSV any time. Cancel and we'll delete it on request.

Plain English

What we do and don't do with your data.

We don't
  • Store payment credentials. We use Stripe.
  • Sell your data to brokers, sportsbooks, or anyone else.
  • Train AI models on your records.
  • Read any inbox. Once we ship email forwarding, parsing is opt-in and per-message.
  • Share your data with co-owners outside the seasons you assigned.
We do
  • Encrypt every record at rest with AES-256.
  • Encrypt all traffic in transit with TLS 1.3.
  • Run row-level security in our database (Postgres/Supabase).
  • Log every change with attribution and timestamp.
  • Delete your data on request, within 30 days.
Hosting
Vercel + Supabase

Production runs on enterprise-grade infrastructure with SOC 2 Type II–certified providers.

Auth
Clerk

Identity by Clerk. SOC 2 Type II, GDPR-ready, MFA built in.

Payments
Stripe

PCI-DSS Level 1. We never see, store, or touch payment credentials.

Responsible disclosure

Found something? We want to know.

If you believe you've found a security vulnerability, email security@seatledger.ai. We'll acknowledge within 24 hours and keep you informed through resolution.

Track your seats with peace of mind.