Security and Trust

Built to protect the decisions, data and people behind the game.

Security has been part of the sfera0 architecture from day one — one set of principles covers every product in the ecosystem: privacy, access, data isolation and day-to-day operations.

Data privacy & GDPR

GDPR compliance and data sovereignty in the EU

  • Data hosted in EU regions
  • Club data remains private and isolated
  • Data subject rights (Art. 15/17/20)
  • Sub-processor registry (Art. 28)
  • Zero internal access (provider/processor split)

Identity & access management

Access control and multi-factor authentication

  • Role-Based Access Control (RBAC)
  • Multi-Factor Authentication (MFA)
  • Field-Level Access Control
  • Server-Side Token Revocation
  • Least-Privilege IAM
  • Identity-Aware Proxy for admins

Data isolation & encryption

Multi-layered isolation and end-to-end encryption

  • Postgres Row-Level Security (RLS)
  • Application-Layer Tenant Scoping
  • AES-256 Encryption at Rest
  • TLS 1.3 Encryption in Transit
  • Mutual TLS (mTLS) for Database
  • Centralized Secrets Management

Operational security

Application protection and business continuity

  • Web Application Firewall (OWASP CRS)
  • DDoS Protection & Rate Limiting
  • HTTP Security Headers (HSTS, CSP)
  • Network Isolation (Private IP, VPC)
  • Immutable audit log
  • High availability — database in two EU zones

At the product level

Different data, the same principle.

Each sfera0 product works with a different data profile — and carries safeguards designed for exactly that profile.

sfera0Voice

Works with the coach's voice and team communication.

  • Zero raw-audio retention — recordings are not stored after processing
  • The coach's reflection stays private
  • Processing based on participants' consent
sfera0Hub

Works with club data — load, health and player availability.

  • Club-level data isolation (Row-Level Security)
  • Access to player data by role and responsibility
  • Immutable log of data operations

Cloud infrastructure

Independently audited infrastructure.

Sfera0 runs on Google Cloud infrastructure covered by internationally recognised security, privacy and AI management standards.

ISO/IEC 27001ISO/IEC 27017ISO/IEC 27018ISO/IEC 27701ISO/IEC 42001 · AI ManagementSOC 2 Type II

These standards apply to the underlying Google Cloud infrastructure.

Questions about security?

We're happy to walk your team through the architecture, data processing agreements and rollout details.

Get in touch