Security
Security built around roles, not an afterthought bolted on.
Stevera OS separates what each role can access at the application layer — university staff and athletes each operate against the same institutional record, scoped by role.
Current Application Controls
Controls in place today.
Role-Based Access Control
Application access is scoped by role and institution. University staff and athletes each work against a different, permission-scoped slice of the same institutional record, so a user sees only the application data and actions their responsibilities require.
Athlete Data Isolation
The current permission model is built on least-privilege principles — athlete-only information stays outside institutional views that don't need it, and institution-scoped data stays outside another institution's view.
Authenticated Sessions
Token-based authentication with hashed credentials, scoped separately for officer and athlete login paths.
Structured Audit Trail
Financial workflow, approval, and administrative actions are captured in a structured audit trail that supports evidence export and reporting review.
Deployment-Dependent Controls
Verified at the deployment level, not the application level.
These controls depend on how and where the platform is hosted. They are not published as implemented until the actual production hosting and database environments are verified.
Encryption in Transit
Production deployments are configured to use HTTPS/TLS for data in transit.
Encryption at Rest
Production deployment requires infrastructure-provider encryption at rest; configuration is verified at deployment.
Assurance Status
Where our assurance program stands today.
Incident Response
A documented, tested incident response process is in development; formal testing is not yet complete.
SOC 2
Stevera has not completed a SOC 2 audit and does not claim SOC 2 certification.
Independent Security Review
An independent third-party security review of the platform has not yet been completed.
Vendor Risk Management
A formal, documented vendor risk review process for payment and infrastructure partners is being formalized.
Payment Infrastructure Security Review
A joint security review with the integrated payment infrastructure provider is planned ahead of any live, connected execution.
Security claims on this page are limited to the status described above — no certification, standard, or independent test result is implied beyond what is stated here.
