Security and privacy.
Read more about how we work with security, integrity and confidentiality.
Infrastructure
Production servers, databases and related services are hosted on Amazon Web Services (AWS).
Application security
Protected with robust encryption, a WAF, and careful testing and review.
Product security
Authentication built on OpenID and OAuth 2.0, audit logs, secure storage and backups.
Operational security
Processes and routines for training, access control and incident response.
Data & privacy
GDPR compliance, access management, data retention and the right to be forgotten.
Infrastructure
Amazon Web Services
Lime Sportadmin uses Amazon Web Services (AWS), one of the world's leading cloud platforms, to host production servers, databases and related services. AWS guarantees advanced encryption and real-time monitoring, and complies with global security standards such as ISO 27001 and the GDPR.
Information about the security measures and routines provided by AWS is available on the AWS security site, while security audits and certifications, such as ISO 27001 certification and SOC reports, are available on the AWS compliance site.
Application security
Protection in layers
Encryption
All data is encrypted in transit with TLS (Transport Layer Security) 1.2 or higher. Data stored in databases and backups is protected with AES-256 encryption, one of the strongest encryption standards, used by banks and public authorities around the world.
Web Application Firewall
To protect the application we use a WAF. It acts as a smart filter between the internet and our systems, blocking suspicious traffic to prevent, for example, DDoS attacks, SQL injections and XSS attacks.
Logical access
Access to production environments is strictly controlled and limited to authorised staff on a strict need-to-know basis. All access requires, among other things, multi-factor authentication (MFA).
Testing and reviews
Changes to the application go through careful testing and review before they are deployed to the production environment. Critical changes always get extra attention.
Product security
Security in the product
Authentication
Our authentication system is built on OpenID and OAuth 2.0. Administrators and instructors log in with a username and password. Members signing in to the app authenticate with a one-time code sent by email.
Administrators can enable two-factor authentication (2FA) through authenticator apps when signing in on the web.
Audit logs
Administrators get access to logs, letting them see account-related activity and, for example, investigate potentially suspicious behaviour or troubleshoot access.
Storage
We use immutable S3 storage for backups, which means data cannot be changed or deleted for a set period of time. This protects against external attacks as well as accidental mistakes that could otherwise result in data loss or encrypted data.
Backup frequency
Full backups are taken daily so that we can restore the system when needed. We also back up transaction logs several times an hour, enabling fast recovery and minimising data loss in an incident.
Operational security
Processes and routines
Access control
Access to all key IT services used by Lime Sportadmin is managed centrally and protected by multi-factor authentication (MFA) and other relevant security measures. These services can only be reached from compliant company devices, ensuring that unauthorised access is prevented. All employees have signed confidentiality agreements covering the handling of personal data, to ensure that information processed in our systems is handled securely and responsibly.
Training and routines
All Lime Sportadmin employees are trained in and required to follow the relevant information-security policies and procedures. Every employee also takes part in mandatory annual security training.
Incident response
Lime Sportadmin has a documented process for identifying, handling and following up on incidents.
Privacy and GDPR
Privacy, access & GDPR
Access and role management
Administrators can define permissions per role or individual, ensuring fine-grained control over access levels and the handling of sensitive data.
Data retention
Administrators can clean up and remove records for people who are no longer active at the school, ensuring the stored data stays relevant and up to date.
The right to be forgotten, erased and to data access
Administrators have access to all information about a specific member and can delete the data if the member asks to be removed from the system.