OT Elevate

Information security program

Last updated: September 24, 2026

Summary. This is OverTime Sport Operations, LLC’s written information security program. It is deliberately sized to what a very small company can actually do every day rather than what a large one can put in a brochure: few people with access, strong defaults, encryption everywhere, backups that can be restored and that honor deletions, logs that show who did what, a written plan for a bad day, and one review a year. It is published because a family deserves to check it, and because writing it down is what makes it real.

Scope: the OT Elevate app, the backend service, the database, the data pipelines, the backups, and the vendor accounts used to run them.

Owner: the Company’s principal, who is the security officer for this program. The Company has no second person today, so there is no deputy; if that changes, this page will name them.

1. Access control#

2. Secrets#

3. Encryption#

4. Backups, restore, and deleting from backups#

Deletion-from-backups procedure. When a parent deletes data or an account:

  1. The record is deleted from the production database and from object storage immediately, and the app stops showing it at once.
  2. A deletion entry — identifiers only, no content — is written to a deletion ledger, with the timestamp and scope of what was deleted.
  3. The deleted data ages out of the backup rotation, gone from every backup copy within 35 days, and the ledger entry’s clock confirms it.
  4. If a backup is restored for any reason, the restore is not complete until the deletion ledger is replayed against the restored data: every deletion recorded since that backup was taken is re-applied before the restored system is allowed to serve traffic. This step is part of the restore runbook and part of the twice-yearly restore test.
  5. The deletion ledger itself is retained for 24 months and contains no personal content.

5. Logging and audit#

The alert definitions are kept as files with the cloud setup runbook (docs/runbooks/cloud-setup.md §14), so what runs is what is written here. - Logs are reviewed weekly at a glance and in full during any incident.

6. Change and development security#

7. Incident response#

An incident is any suspected unauthorized access to customer data, loss of data, or compromise of a credential or vendor account.

Stage Target
Detect and declare Immediately on discovery; the principal is the incident lead
Contain — rotate credentials, revoke sessions, isolate systems Within 4 hours of declaration
Assess what data and which accounts are affected Within 24 hours
Notify affected users Without unreasonable delay, and no later than 72 hours after we confirm personal information was affected
Notify regulators and attorneys general Within the deadlines the applicable state and federal laws require
Notify affected vendors and the app store As their agreements require
Written post-incident review, with the fix and the date it shipped Within 14 days of containment

8. Vendor review#

9. People#

10. Annual review#

Once a year, in September, the whole program is reviewed and re-dated:

  1. Walk every section above and correct anything that is no longer true.
  2. Run the access review and the restore test, and record both.
  3. Review the vendor list and the processor table.
  4. Review the retention schedule against what the systems actually delete — pick a few categories and verify.
  5. Review the incident log and the post-incident fixes.
  6. Rehearse the incident runbook.
  7. Re-date this document and Retention schedule.

A review that finds nothing wrong is a review that was not done properly.

Contact#

Security reports, including vulnerability reports, go to support@otsportops.com with “security” in the subject. We will acknowledge within 48 hours and we will not pursue anyone who reports a vulnerability to us in good faith and does not access or damage other people’s data.