Security.
Last updated August 26, 2026
TrackForge holds training, performance and health-adjacent information about athletes, including minors. We take reports about our security seriously and we would rather hear from you than not.
1. Reporting a vulnerability
Email security@trackforge.fit. Please include:
- What you found and where. A URL or endpoint helps.
- How to reproduce it. The steps you took, in order.
- What an attacker could do with it. Your assessment of the impact.
- How you would like to be credited. If at all. Credit is yours to decline.
Encrypted reports are welcome. Ask us for a key.
2. What happens next
- Within 3 days. We acknowledge your report.
- Within 10 days. We tell you whether we have reproduced it, and our assessment.
- As we work. We keep you updated at least every 14 days until it is closed.
- On resolution. We tell you it is fixed, and credit you if you want credit.
If an update is late, reply to the report thread or email security@trackforge.fit again.
3. Safe harbour
If you follow this policy in good faith, we will not pursue legal action against you, and we will say so if a third party asks.
Please do:
- Test only your own accounts and data. Yours, not somebody else’s.
- Stop as soon as you have confirmed a vulnerability. Proving it exists is enough. Going further is not.
- Give us reasonable time before telling anyone else. We suggest 90 days, and we will work with you if a fix takes longer.
Please do not:
- Access, modify, download or keep another person's data. If you encounter athlete data that is not yours, stop immediately and tell us what you saw so we can assess it. Do not keep a copy.
- Run denial of service tests, spam, or brute force attacks. Availability is part of what athletes rely on.
- Use social engineering. Against our team, our customers or our vendors.
- Test physical security or third-party property. Neither is ours to authorise.
4. Scope
In scope: the TrackForge web application and its backend, and our published websites.
Out of scope: the infrastructure of our service providers. If you find a vulnerability in one of the companies listed on our subprocessors page, please report it to them directly. Tell us too if it affects TrackForge.
Also out of scope, unless you can show real impact: missing security headers on their own, reports produced only by an automated scanner, best-practice suggestions with no exploit path, and issues requiring a compromised device or a physically present attacker.
5. Rewards
We do not currently run a paid bug bounty.
What we do offer: a fast, human response, public credit if you want it, and a straight answer about what we fixed and when.
6. Reporting a privacy concern
Security reports go to security@trackforge.fit. For questions about how your data is handled, to request a copy of your data, or to ask for it to be deleted, write to privacy@trackforge.fit or see our Privacy Policy.
If you are a student-athlete at a school or university that uses TrackForge and you have a concern about how your data is being used, you can write to us, and you can also raise it with your athletics department. Institutions that use TrackForge decide how the product is configured and who can see what, and many run an athlete data governance committee for exactly this purpose. Institutions configure access within TrackForge’s role and policy limits. We follow lawful instructions and applicable privacy law.
7. Our security posture
Current controls and limits:
- Our providers hold independent attestations. Convex and Clerk publish SOC 2 Type II attestations and conduct independent security testing.
- We store no passwords. Authentication is handled by a specialist provider.
- Access to protected product data is authorised on the server against the requester’s role and athlete scope.
- Our public privacy and subprocessor pages identify the data categories and providers used by the product.
- TrackForge holds no SOC 2 attestation of its own and has not commissioned an independent penetration test.
Institutional customers can request our full security documentation, including our HECVAT response and our data security plan, by writing to security@trackforge.fit.
8. Machine-readable contact
The same contact details are published at /.well-known/security.txt in the format described by RFC 9116, for scanners and researchers who look there first.