Compliance

We help university IT, security, accessibility, and procurement teams evaluate EquipCheck for their institution. Here you can review our accessibility status, download our assessment documents, and learn how we protect your data. If your review requires additional information, contact us at support@equipchecksoftware.com.

HECVAT

We provide our completed Higher Education Community Vendor Assessment Toolkit (HECVAT) Lite 2.11, dated April 16, 2025, to support your institution’s vendor security review. Download our responses below, and contact us if your team needs clarification or additional documentation.

Accessibility (VPAT)

We assess EquipCheck against the Web Content Accessibility Guidelines (WCAG) 2.0 and the Revised Section 508 standards. Our February 6, 2026 Accessibility Conformance Report (VPAT) explains which requirements we support and where accessibility gaps remain.

WCAG 2.0 Level AA: Partially supported. We support many Level A and AA requirements, but we do not yet meet all requirements for full AA conformance. Our VPAT provides the details for your accessibility review.

Revised Section 508: Supported with documented exceptions. We do not meet every applicable requirement. We document our supported, partially supported, and unsupported requirements in the VPAT so your team can evaluate them against your institution’s needs.

Terms of Service

Our terms of service describe the terms and conditions for using EquipCheck. Please include them in your institution’s legal and procurement review.

Privacy Policy

Our privacy policy explains how we collect, use, and manage personal data when you use EquipCheck. Please include it in your institution’s privacy review.

Security Policy

EquipCheck Security & Privacy Overview

Downloadable overview: Version 1.0, May 11, 2025.

We summarize our security practices below to help with your review. This page includes updated information on hosting, sign-in options, releases, and our 2027 security plans. Our downloadable overview retains its original May 2025 date.

1 | About EquipCheck

Item Detail
Legal Entity EquipCheck, LLC
Headquarters We are a fully remote organization based in the United States.
Primary Product We provide cloud-based athletic equipment inventory software for university and professional teams, with web and mobile applications.
Contact (Security & Privacy) support@equipchecksoftware.com

2 | Governance & Written Policies

We maintain written information security policies covering access, data handling, software development, incident response, and business continuity. We keep these policies in a private repository, require executive approval for revisions, and review them on the schedule below.

Policy or Standard Scope Review Schedule
Information-Security Policy Security principles and responsibilities Annual
Data-Classification & Handling Standard Requirements for storing, transmitting, and deleting data Annual
Access-Control / Least-Privilege Standard Access provisioning, multifactor authentication, and role reviews Quarterly
Secure-Development Guidelines Code review and software dependency management Release-based
Change-Management Standard Change review, impact assessment, and rollback procedures Annual
Incident-Response Plan (IRP) Incident detection, containment, remediation, recovery, and customer notification Annual incident-response exercise
Business-Continuity & Disaster-Recovery Plan Weekly backups, 12-month retention Backup restoration testing twice a year
Privacy & Data-Protection Policy Privacy practices and deletion within 30 days of contract termination Annual

3 | Hosting & Infrastructure

Topic Detail
Cloud Provider & Region We host EquipCheck on Google Cloud in us-central1 (Iowa).
Compute Model Our backend runs on Google App Engine.
Data Storage & Back-ups We store application data in Google Cloud Datastore/Firestore with AES-256 encryption at rest. We run weekly backups to Cloud Storage; our documented backup retention period is 12 months.
Network & Transit Security We use TLS 1.2 or later for external connections and Google-managed mutual TLS for internal service connections.
Administration We use Google Workspace single sign-on and require multifactor authentication for administration.
Application Releases We use pull requests to review changes and an automated release workflow to verify and deploy the application to App Engine.

4 | Your Data & How We Use It

Data Type Do We Store It? Notes
Player and staff names, email addresses, and phone numbers Yes Confidential
Player clothing and equipment sizes Yes Confidential
Inventory item names, sizes, and quantities Yes Internal
Payment, biometric, and health data No

Service delivery. We access your data to operate EquipCheck and respond to your support requests.

Analytics. We retain aggregate, de-identified metrics without direct identifiers for ongoing analysis.

Testing. Our documented practice is to use synthetic data in staging and test environments rather than copies of production data.

Retention and deletion. Our documented policy is to delete live customer data within 30 days of contract termination or a written deletion request. Backup copies expire 12 months after creation.

5 | Security Controls

Area Control
Authentication We support username-and-password sign-in and SAML single sign-on. Account administrators can configure single sign-on and SMS or email multifactor authentication as optional or required.
Least-Privilege We use role-based access controls and review access quarterly.
Encryption We protect data in transit with TLS 1.2 or later and data at rest with AES-256 encryption using Google-managed keys.
Vulnerability Management We monitor configuration and dependency alerts through Google Cloud Security Command Center and apply patches during maintenance windows.
Penetration Testing We have not yet completed a penetration test. We plan to conduct third-party testing in 2027. Contact us if your institution requires testing information as part of its review.
Employee Background Checks We complete background checks before granting personnel access to production systems.
Training We plan to introduce a formal role-based security training program in 2027. This program is not yet in place.

6 | Incident Detection & Response

Monitoring. We bring security, audit-log, availability, and error alerts into a shared alert channel with escalation to the on-call team.

Response process. We follow a documented incident-response plan to identify, contain, resolve, and recover from incidents. The plan includes severity levels, communication templates, and a 72-hour customer-notification commitment.

Investigation. Our CTO and on-call engineer lead triage and investigation using cloud logs and BigQuery. For major incidents, our response resources include Google Cloud incident-response specialists and retained external consultants.

Keeping you informed. Our documented commitments are an initial notice within 72 hours, periodic updates during the response, and a root-cause report within 10 business days.

7 | Audit & Risk Management

Internal reviews. We review the systems and processes that handle customer data quarterly, including policies, access permissions, security findings, backup restoration, changes, and incident records.

Review scope. These reviews cover customer-data systems. Non-production marketing assets and test environments containing only synthetic data are outside that scope.

Independent assessments. We have not yet completed an independent audit or obtained a SOC 2 report for EquipCheck. We plan to pursue a SOC 2 Type I assessment in 2027. Our cloud providers’ assurance reports apply to their services; they do not establish EquipCheck’s own certification or audit status.

Risk management. We use ongoing security monitoring and quarterly reviews to identify and address risks. We plan to document a formal risk-assessment methodology aligned with NIST in 2027; that methodology is not yet in place.

8 | Personnel Security

We restrict production-data access to authorized personnel. Our personnel security practices include:

We plan to formalize our onboarding, offboarding, and role-based security training documentation in 2027. Contact us if your review requires details about our existing personnel security practices.

9 | Service Providers

Provider Function Provider Assurance
Google Cloud Platform Hosting, storage, and access management SOC 2 Type II, ISO 27001
Amazon SES (AWS) Transactional email SOC 2 Type II, ISO 27001

We use Google Cloud for hosting and Amazon Simple Email Service (SES) for transactional email. We review provider certifications and security bulletins annually. We plan to add a formal vendor assessment questionnaire and contract checklist in 2027. Contact us for the provider information your institution requires, including any review of optional integrations.

10 | Change Management

We manage our infrastructure and application code in version control.

We classify changes as standard, high-impact, or emergency to determine the review, approval, rollback, and deployment process.

We retain change-review discussions and cloud audit logs as records of development and administrative activity.

We review emergency fixes within 24 hours after deployment.

11 | Documented Customer Commitments

Commitment Our Commitment
Encryption TLS 1.2+ in transit; AES-256 at rest
Backup Retention 12 months
Data Deletion Within 30 days of contract termination
Customer Incident Notice Within 72 hours
Post-Incident Report Within 10 business days

12 | Completing Your Review

We can help your security, accessibility, and procurement teams review our documentation and understand how EquipCheck fits your institution’s requirements.

Start with our VPAT for accessibility requirements and our HECVAT for vendor security questions. Our security overview provides additional detail on data handling, access controls, incident response, and business continuity.

Please identify any requirements that need further evidence or clarification, including data retention, incident notification, independent assessments, or accessibility exceptions.

For answers to your review questions or to request redacted policy documents under a nondisclosure agreement, contact us at support@equipchecksoftware.com.