Compliance
We help university IT, security, accessibility, and procurement teams evaluate EquipCheck for their institution. Here you can review our accessibility status, download our assessment documents, and learn how we protect your data. If your review requires additional information, contact us at support@equipchecksoftware.com.
HECVAT
We provide our completed Higher Education Community Vendor Assessment Toolkit (HECVAT) Lite 2.11, dated April 16, 2025, to support your institution’s vendor security review. Download our responses below, and contact us if your team needs clarification or additional documentation.
Accessibility (VPAT)
We assess EquipCheck against the Web Content Accessibility Guidelines (WCAG) 2.0 and the Revised Section 508 standards. Our February 6, 2026 Accessibility Conformance Report (VPAT) explains which requirements we support and where accessibility gaps remain.
WCAG 2.0 Level AA: Partially supported. We support many Level A and AA requirements, but we do not yet meet all requirements for full AA conformance. Our VPAT provides the details for your accessibility review.
Revised Section 508: Supported with documented exceptions. We do not meet every applicable requirement. We document our supported, partially supported, and unsupported requirements in the VPAT so your team can evaluate them against your institution’s needs.
Terms of Service
Our terms of service describe the terms and conditions for using EquipCheck. Please include them in your institution’s legal and procurement review.
Privacy Policy
Our privacy policy explains how we collect, use, and manage personal data when you use EquipCheck. Please include it in your institution’s privacy review.
Security Policy
EquipCheck Security & Privacy Overview
Downloadable overview: Version 1.0, May 11, 2025.
We summarize our security practices below to help with your review. This page includes updated information on hosting, sign-in options, releases, and our 2027 security plans. Our downloadable overview retains its original May 2025 date.
1 | About EquipCheck
| Item | Detail |
|---|---|
| Legal Entity | EquipCheck, LLC |
| Headquarters | We are a fully remote organization based in the United States. |
| Primary Product | We provide cloud-based athletic equipment inventory software for university and professional teams, with web and mobile applications. |
| Contact (Security & Privacy) | support@equipchecksoftware.com |
2 | Governance & Written Policies
We maintain written information security policies covering access, data handling, software development, incident response, and business continuity. We keep these policies in a private repository, require executive approval for revisions, and review them on the schedule below.
| Policy or Standard | Scope | Review Schedule |
|---|---|---|
| Information-Security Policy | Security principles and responsibilities | Annual |
| Data-Classification & Handling Standard | Requirements for storing, transmitting, and deleting data | Annual |
| Access-Control / Least-Privilege Standard | Access provisioning, multifactor authentication, and role reviews | Quarterly |
| Secure-Development Guidelines | Code review and software dependency management | Release-based |
| Change-Management Standard | Change review, impact assessment, and rollback procedures | Annual |
| Incident-Response Plan (IRP) | Incident detection, containment, remediation, recovery, and customer notification | Annual incident-response exercise |
| Business-Continuity & Disaster-Recovery Plan | Weekly backups, 12-month retention | Backup restoration testing twice a year |
| Privacy & Data-Protection Policy | Privacy practices and deletion within 30 days of contract termination | Annual |
3 | Hosting & Infrastructure
| Topic | Detail |
|---|---|
| Cloud Provider & Region | We host EquipCheck on Google Cloud in us-central1 (Iowa). |
| Compute Model | Our backend runs on Google App Engine. |
| Data Storage & Back-ups | We store application data in Google Cloud Datastore/Firestore with AES-256 encryption at rest. We run weekly backups to Cloud Storage; our documented backup retention period is 12 months. |
| Network & Transit Security | We use TLS 1.2 or later for external connections and Google-managed mutual TLS for internal service connections. |
| Administration | We use Google Workspace single sign-on and require multifactor authentication for administration. |
| Application Releases | We use pull requests to review changes and an automated release workflow to verify and deploy the application to App Engine. |
4 | Your Data & How We Use It
| Data Type | Do We Store It? | Notes |
|---|---|---|
| Player and staff names, email addresses, and phone numbers | Yes | Confidential |
| Player clothing and equipment sizes | Yes | Confidential |
| Inventory item names, sizes, and quantities | Yes | Internal |
| Payment, biometric, and health data | No | — |
Service delivery. We access your data to operate EquipCheck and respond to your support requests.
Analytics. We retain aggregate, de-identified metrics without direct identifiers for ongoing analysis.
Testing. Our documented practice is to use synthetic data in staging and test environments rather than copies of production data.
Retention and deletion. Our documented policy is to delete live customer data within 30 days of contract termination or a written deletion request. Backup copies expire 12 months after creation.
5 | Security Controls
| Area | Control |
|---|---|
| Authentication | We support username-and-password sign-in and SAML single sign-on. Account administrators can configure single sign-on and SMS or email multifactor authentication as optional or required. |
| Least-Privilege | We use role-based access controls and review access quarterly. |
| Encryption | We protect data in transit with TLS 1.2 or later and data at rest with AES-256 encryption using Google-managed keys. |
| Vulnerability Management | We monitor configuration and dependency alerts through Google Cloud Security Command Center and apply patches during maintenance windows. |
| Penetration Testing | We have not yet completed a penetration test. We plan to conduct third-party testing in 2027. Contact us if your institution requires testing information as part of its review. |
| Employee Background Checks | We complete background checks before granting personnel access to production systems. |
| Training | We plan to introduce a formal role-based security training program in 2027. This program is not yet in place. |
6 | Incident Detection & Response
Monitoring. We bring security, audit-log, availability, and error alerts into a shared alert channel with escalation to the on-call team.
Response process. We follow a documented incident-response plan to identify, contain, resolve, and recover from incidents. The plan includes severity levels, communication templates, and a 72-hour customer-notification commitment.
Investigation. Our CTO and on-call engineer lead triage and investigation using cloud logs and BigQuery. For major incidents, our response resources include Google Cloud incident-response specialists and retained external consultants.
Keeping you informed. Our documented commitments are an initial notice within 72 hours, periodic updates during the response, and a root-cause report within 10 business days.
7 | Audit & Risk Management
Internal reviews. We review the systems and processes that handle customer data quarterly, including policies, access permissions, security findings, backup restoration, changes, and incident records.
Review scope. These reviews cover customer-data systems. Non-production marketing assets and test environments containing only synthetic data are outside that scope.
Independent assessments. We have not yet completed an independent audit or obtained a SOC 2 report for EquipCheck. We plan to pursue a SOC 2 Type I assessment in 2027. Our cloud providers’ assurance reports apply to their services; they do not establish EquipCheck’s own certification or audit status.
Risk management. We use ongoing security monitoring and quarterly reviews to identify and address risks. We plan to document a formal risk-assessment methodology aligned with NIST in 2027; that methodology is not yet in place.
8 | Personnel Security
We restrict production-data access to authorized personnel. Our personnel security practices include:
- Background screening before employment
- Signed confidentiality and intellectual-property agreements
- Role-based access limited to job responsibilities and protected by multifactor authentication
- Same-day access revocation when personnel leave
We plan to formalize our onboarding, offboarding, and role-based security training documentation in 2027. Contact us if your review requires details about our existing personnel security practices.
9 | Service Providers
| Provider | Function | Provider Assurance |
|---|---|---|
| Google Cloud Platform | Hosting, storage, and access management | SOC 2 Type II, ISO 27001 |
| Amazon SES (AWS) | Transactional email | SOC 2 Type II, ISO 27001 |
We use Google Cloud for hosting and Amazon Simple Email Service (SES) for transactional email. We review provider certifications and security bulletins annually. We plan to add a formal vendor assessment questionnaire and contract checklist in 2027. Contact us for the provider information your institution requires, including any review of optional integrations.
10 | Change Management
We manage our infrastructure and application code in version control.
We classify changes as standard, high-impact, or emergency to determine the review, approval, rollback, and deployment process.
We retain change-review discussions and cloud audit logs as records of development and administrative activity.
We review emergency fixes within 24 hours after deployment.
11 | Documented Customer Commitments
| Commitment | Our Commitment |
|---|---|
| Encryption | TLS 1.2+ in transit; AES-256 at rest |
| Backup Retention | 12 months |
| Data Deletion | Within 30 days of contract termination |
| Customer Incident Notice | Within 72 hours |
| Post-Incident Report | Within 10 business days |
12 | Completing Your Review
We can help your security, accessibility, and procurement teams review our documentation and understand how EquipCheck fits your institution’s requirements.
Start with our VPAT for accessibility requirements and our HECVAT for vendor security questions. Our security overview provides additional detail on data handling, access controls, incident response, and business continuity.
Please identify any requirements that need further evidence or clarification, including data retention, incident notification, independent assessments, or accessibility exceptions.
For answers to your review questions or to request redacted policy documents under a nondisclosure agreement, contact us at support@equipchecksoftware.com.