Security & trust

Payments, data, and access

Production practices across SportsCove and enterprise surfaces. Formal certifications follow customer demand.

Controls

Live vs roadmap

  • TLS / HTTPSLive
  • Payment PCI (processors)Live
  • API rate limitingLive
  • Consent-gated analyticsLive
  • security.txtLive
  • Public status pageLive
  • Accessibility statement (WCAG 2.1 AA target)Live
  • SOC 2 Type IRoadmap
  • Pen test reportRoadmap
  • EU DPAsRoadmap
  • Branded product domains (*.consultcraftinc.com)Roadmap

Practices

How we run production

Payments, data, infrastructure, access, and reporting — written for enterprise buyers and auditors.

Payments

  • Stripe and Razorpay process coach payouts — ConsultCraft does not store card numbers.
  • Marketplace fees applied at booking completion — 15% platform fee; processors, taxes, and store billing billed separately.
  • Webhook verification and idempotent payment handlers in production.

Data handling

  • Privacy policies per product line — corporate, SportsCove, MechCove, FlowAI.
  • Firebase Analytics for product usage; consent-gated site analytics on consultcraftinc.com.
  • Investor portal and admin routes are password-gated and noindex.

Infrastructure

  • Hosted on Vercel with TLS everywhere; canonical domain redirect from preview URLs.
  • API rate limiting on auth, analytics, media, and investor registry endpoints.
  • Environment secrets managed via platform env vars — never committed to git.

Access control

  • Separate investor and admin auth tokens with idle timeout in portal.
  • Content protection on gated materials; coach media uploads via authenticated API.
  • Robots.txt blocks portal, admin, developers, and API paths from indexing.

Reporting issues

  • security.txt at /.well-known/security.txt
  • Report vulnerabilities to info@consultcraftinc.com
  • SportsCove user support: sc-support@consultcraftinc.com

Roadmap

What comes next

Sequenced by stage — Type I before Type II, pilots before full DPAs.

Phase

Now

  • Public trust center + security.txt
  • TLS everywhere · API rate limits · env-only secrets
  • Password-gated investor portal with idle timeout
  • Stripe / Razorpay PCI scope stays with processors

Phase

Post-Seed (0–6 months)

  • SOC 2 Type I scoping with readiness questionnaire
  • Vendor DPA pack for enterprise FlowAI buyers
  • Quarterly access review for portal and admin roles

Phase

Pre-Series A

  • Independent penetration test with remediation report under NDA
  • SOC 2 Type I observation period complete
  • EU data processing agreements for expansion markets