Security
Security built around roles, not an afterthought bolted on.
Stevera OS separates what each role can access at the application layer — university staff, athletes, and agents each operate against the same institutional record, scoped by role.
Implemented
Controls in place today.
Role-Based Access Control
Application access is scoped by role across university, athlete, and agent experiences. University staff, athletes, and agents each work against a different, permission-scoped slice of the same institutional record.
Athlete Data Isolation
The current permission model is designed not to expose athlete balances, banking details, tax-reserve information, or transaction history to university staff or agents.
Authenticated Sessions
Token-based authentication with hashed credentials, scoped separately for officer, athlete, and agent login paths.
Structured Audit Trail
Compliance, disclosure, and approval actions are captured in a structured audit trail that supports evidence export.
Deployment-Dependent Controls
Verified at the deployment level, not the application level.
These controls depend on how and where the platform is hosted. They are not published as implemented until the actual production hosting and database environments are verified.
Encryption in Transit
Production deployments are configured to use HTTPS/TLS for data in transit.
Encryption at Rest
Production data stores are expected to use infrastructure-provider encryption at rest, subject to deployment verification.
In Collaborative Development
Underway, not yet complete.
Formal Incident Response Plan
A documented, tested incident response process is in development.
SOC 2 Preparation
We are preparing our controls environment with SOC 2 in mind. We have not completed a SOC 2 audit and do not claim certification.
Third-Party Security Review
Independent security review and testing of the platform is planned but not yet completed.
Planned
On the roadmap.
Vendor Risk Management Program
A formal, documented vendor risk review process for banking and infrastructure partners.
Banking-Partner Security Integration Review
Joint security review with a banking partner ahead of any live, connected execution integration.
Stevera OS is a working prototype under active development. Controls above are described accurately as implemented, deployment-dependent, in collaborative development, or planned — nothing here should be read as claiming more than that, including any certification, standard, or independent test result not actually achieved.
