Skip to main content
Dropback

Security / Private by design

Industry-leading security and privacy practices.

Dropback gives athletic departments a private, permissioned Workspace for your data. Customer information stays isolated, encrypted, and controlled by the institution.

Built by U.S.-based engineers with experience at leading software companies.

HudlMetaMicrosoft

Data commitments

Customer data remains under your ownership and control.

01

Never sold

Your private customer data is never sold or made available to another customer.

02

Zero data training

Your private data is not used to train Dropback or third-party foundation models. Enterprise provider agreements also require zero data retention (ZDR).

03

You own it

You retain ownership of your non-public customer data and control how it is managed.

04

Portable

Export your data before termination, with retention and deletion handled according to your agreement.

Data protection

Customer data is encrypted in transit and at rest.

Your compensation data, student-athlete records, evaluations, and strategic plans are protected across storage, access, and lifecycle.

Data encryption

Customer data is protected with TLS 1.2 encryption in transit and AES-256 encryption at rest.

Reliable infrastructure

Dropback runs on enterprise cloud infrastructure with controls designed for sensitive institutional data.

Customer data ownership

You retain ownership of all Customer Data. Dropback never sells, redistributes, sublicenses, or makes it available to another customer or third party.

Student-athlete data guardrails

Dropback agrees to the requirements of the Family Educational Rights and Privacy Act (FERPA), where applicable, when handling student-athlete data.

Data lifecycle controls

Non-public customer data is retained for 30 days after termination to allow export, then may be deleted or archived.

Access and governance

Control access by user and role.

Provision staff according to responsibility, then govern what they can see and change across the Workspace.

SSO available

Connect a supported identity provider such as Duo, Okta, or Microsoft for secure sign-on on eligible paid plans.

Secure authentication

Connect SSO, or use Dropback authentication with secure defaults including: MFA, configurable password requirements, or magic links.

User provisioning

Invite staff into limited or full team and Workspace access according to their responsibilities.

Audit history

Review important Workspace events across a rolling 90-day history.

Role-based access control

Customizable RBAC allows administrators to provision access and control who can read or write sensitive data.

Custom read/write permissions

Row-level security (RLS) and granular permissions control what each user can read or update across datasets, tables, columns, fields, and views.

Tenant-scoped architecture

Each customer operates in an isolated tenant environment.

Every institution operates inside an isolated tenant environment. One program's private context never becomes another program's intelligence.

01

Enterprise-grade cloud

Cloud-based infrastructure, powered by Amazon Web Services (AWS). Stored customer data is housed 100% in secure United States data centers.

02

Isolated tenant environment

Information provided, uploaded, or imported by your institution remains scoped to your tenant.

03

Encrypted at every layer

Your private data environment is protected in transit and at rest.

04

Protected access

Logical and infrastructure controls prevent unauthorized access by anyone—including Dropback staff outside authorized support scenarios.

Secure AI infrastructure

Enterprise-grade AI guardrails

These controls apply to every AI request that processes customer data.

Temporary, isolated sandbox

Each AI request runs in a temporary sandbox scoped to the files and datasets authorized for that task.

Zero data retention (ZDR)

Approved model providers process requests under enterprise agreements that prohibit retaining prompts, responses, and customer data after processing.

No model training

Dropback and approved model providers do not use private customer data to train their models.

Task-scoped data access

AI reads only the data needed to complete an authorized task; customer datasets are not bulk-uploaded to a model.

Permissioned data access

Each AI request is limited by the user's access and the datasets and actions authorized for that workflow.

Traceable results

AI-generated answers are based on queries against customer data and can be traced back to the underlying source records.

Institutional review

Additional documentation is available upon request.