01
Never sold
Your private customer data is never sold or made available to another customer.
Security / Private by design
Dropback gives athletic departments a private, permissioned Workspace for your data. Customer information stays isolated, encrypted, and controlled by the institution.
Built by U.S.-based engineers with experience at leading software companies.
Data commitments
01
Your private customer data is never sold or made available to another customer.
02
Your private data is not used to train Dropback or third-party foundation models. Enterprise provider agreements also require zero data retention (ZDR).
03
You retain ownership of your non-public customer data and control how it is managed.
04
Export your data before termination, with retention and deletion handled according to your agreement.
Data protection
Your compensation data, student-athlete records, evaluations, and strategic plans are protected across storage, access, and lifecycle.
Customer data is protected with TLS 1.2 encryption in transit and AES-256 encryption at rest.
Dropback runs on enterprise cloud infrastructure with controls designed for sensitive institutional data.
You retain ownership of all Customer Data. Dropback never sells, redistributes, sublicenses, or makes it available to another customer or third party.
Dropback agrees to the requirements of the Family Educational Rights and Privacy Act (FERPA), where applicable, when handling student-athlete data.
Non-public customer data is retained for 30 days after termination to allow export, then may be deleted or archived.
Access and governance
Provision staff according to responsibility, then govern what they can see and change across the Workspace.
Connect a supported identity provider such as Duo, Okta, or Microsoft for secure sign-on on eligible paid plans.
Connect SSO, or use Dropback authentication with secure defaults including: MFA, configurable password requirements, or magic links.
Invite staff into limited or full team and Workspace access according to their responsibilities.
Review important Workspace events across a rolling 90-day history.
Customizable RBAC allows administrators to provision access and control who can read or write sensitive data.
Row-level security (RLS) and granular permissions control what each user can read or update across datasets, tables, columns, fields, and views.
Tenant-scoped architecture
Every institution operates inside an isolated tenant environment. One program's private context never becomes another program's intelligence.
Cloud-based infrastructure, powered by Amazon Web Services (AWS). Stored customer data is housed 100% in secure United States data centers.
Information provided, uploaded, or imported by your institution remains scoped to your tenant.
Your private data environment is protected in transit and at rest.
Logical and infrastructure controls prevent unauthorized access by anyone—including Dropback staff outside authorized support scenarios.
Secure AI infrastructure
These controls apply to every AI request that processes customer data.
Each AI request runs in a temporary sandbox scoped to the files and datasets authorized for that task.
Approved model providers process requests under enterprise agreements that prohibit retaining prompts, responses, and customer data after processing.
Dropback and approved model providers do not use private customer data to train their models.
AI reads only the data needed to complete an authorized task; customer datasets are not bulk-uploaded to a model.
Each AI request is limited by the user's access and the datasets and actions authorized for that workflow.
AI-generated answers are based on queries against customer data and can be traced back to the underlying source records.
Institutional review