Skip to content

Security and privacy.

Read more about how we work with security, integrity and confidentiality.

Infrastructure

Amazon Web Services

Lime Sportadmin uses Amazon Web Services (AWS), one of the world's leading cloud platforms, to host production servers, databases and related services. AWS guarantees advanced encryption and real-time monitoring, and complies with global security standards such as ISO 27001 and the GDPR.

Information about the security measures and routines provided by AWS is available on the AWS security site, while security audits and certifications, such as ISO 27001 certification and SOC reports, are available on the AWS compliance site.

Amazon Web Services

Application security

Protection in layers

Encryption

All data is encrypted in transit with TLS (Transport Layer Security) 1.2 or higher. Data stored in databases and backups is protected with AES-256 encryption, one of the strongest encryption standards, used by banks and public authorities around the world.

Web Application Firewall

To protect the application we use a WAF. It acts as a smart filter between the internet and our systems, blocking suspicious traffic to prevent, for example, DDoS attacks, SQL injections and XSS attacks.

Logical access

Access to production environments is strictly controlled and limited to authorised staff on a strict need-to-know basis. All access requires, among other things, multi-factor authentication (MFA).

Testing and reviews

Changes to the application go through careful testing and review before they are deployed to the production environment. Critical changes always get extra attention.

Product security

Security in the product

Authentication

Our authentication system is built on OpenID and OAuth 2.0. Administrators and instructors log in with a username and password. Members signing in to the app authenticate with a one-time code sent by email.

Administrators can enable two-factor authentication (2FA) through authenticator apps when signing in on the web.

Google Authenticator
Microsoft Authenticator

Audit logs

Administrators get access to logs, letting them see account-related activity and, for example, investigate potentially suspicious behaviour or troubleshoot access.

Storage

We use immutable S3 storage for backups, which means data cannot be changed or deleted for a set period of time. This protects against external attacks as well as accidental mistakes that could otherwise result in data loss or encrypted data.

Backup frequency

Full backups are taken daily so that we can restore the system when needed. We also back up transaction logs several times an hour, enabling fast recovery and minimising data loss in an incident.

Operational security

Processes and routines

Access control

Access to all key IT services used by Lime Sportadmin is managed centrally and protected by multi-factor authentication (MFA) and other relevant security measures. These services can only be reached from compliant company devices, ensuring that unauthorised access is prevented. All employees have signed confidentiality agreements covering the handling of personal data, to ensure that information processed in our systems is handled securely and responsibly.

Training and routines

All Lime Sportadmin employees are trained in and required to follow the relevant information-security policies and procedures. Every employee also takes part in mandatory annual security training.

Incident response

Lime Sportadmin has a documented process for identifying, handling and following up on incidents.

Privacy and GDPR

Privacy, access & GDPR

Access and role management

Administrators can define permissions per role or individual, ensuring fine-grained control over access levels and the handling of sensitive data.

Data retention

Administrators can clean up and remove records for people who are no longer active at the school, ensuring the stored data stays relevant and up to date.

The right to be forgotten, erased and to data access

Administrators have access to all information about a specific member and can delete the data if the member asks to be removed from the system.