Data Security Policy

Effective Date: August 14, 2026 · Last Updated: August 14, 2026

1. Purpose

Core Sports AI ("Core") recognizes that customers entrust Core with video recordings, athlete information, performance data, account information, and other potentially sensitive information.

This Data Security Policy describes the administrative, technical, and organizational practices Core uses or requires to protect information processed through its Services.

Core's security program is designed to preserve the confidentiality, integrity, and availability of information and reduce the risk of unauthorized access, use, disclosure, modification, loss, or destruction.

2. Scope

This Policy applies to Core's production systems, applications, databases, cloud infrastructure, software-development processes, personnel, contractors, and service providers that process Core customer information.

Additional contractual security requirements may apply to particular enterprise, academy, governing-body, or institutional customers.

3. Security Governance

Core maintains responsibility for its information-security program and evaluates security controls based on the nature of the information processed, foreseeable threats, the sensitivity of athlete and junior-athlete information, the technology used by the Services, and changes to Core's systems and business.

Security responsibilities are assigned to appropriate personnel, and security practices are reviewed as Core's systems, risks, and services evolve.

4. Data Minimization

Core seeks to collect and retain only information reasonably necessary to provide, secure, support, and improve the Services or satisfy legal and contractual obligations.

Core applies heightened consideration to junior-athlete information, video recordings, account credentials, sensitive information, and any information that could create an increased privacy or security risk.

5. Access Control

Access to production systems and customer information is limited to personnel and authorized service providers that require access for legitimate business purposes.

Core follows principles of least privilege and role-appropriate access.

Administrative access is restricted and should be granted only when required for engineering, security, customer support, incident response, infrastructure operations, or other legitimate operational functions.

Access should be removed or modified when personnel change roles or no longer require access.

6. Authentication

Core requires authentication before users can access private accounts and protected customer information.

Core employs controls designed to prevent unauthorized account access and encourages users to use strong, unique passwords and protect their authentication credentials.

Privileged administrative accounts should use stronger authentication protections, including multi-factor authentication where supported by the applicable system.

7. Cloud Infrastructure

Core uses cloud-based infrastructure to host and process information required to operate its Services.

Production information is stored using infrastructure designed for commercial cloud applications, with access restricted through appropriate authentication, permissions, and infrastructure controls.

Core evaluates service providers based on their function, security capabilities, and the sensitivity of information they process.

8. Encryption and Secure Transmission

Core uses encrypted network connections, such as HTTPS/TLS, for the transmission of information between supported user applications and Core's production Services.

Core uses storage and database security capabilities provided by its infrastructure providers to protect production data at rest where applicable.

Credentials, secrets, API keys, and comparable authentication information should not be intentionally exposed in publicly accessible source code.

9. Video Security

Private athlete videos are treated as protected customer content.

Private video access is limited to authorized account users, authorized personnel within a customer's organization where applicable, Core personnel with a legitimate operational need, and contracted service providers required to process the video on Core's behalf.

Core does not intentionally publish private player videos or make them available to unrelated customers.

Where video is temporarily copied, transformed, segmented, cached, or processed as part of the analysis pipeline, those copies remain subject to Core's applicable security and retention controls.

10. Junior-Athlete Information

Information associated with athletes under 18 receives heightened privacy consideration.

Core limits access to junior-athlete content to users and personnel with an appropriate reason for access and does not knowingly sell junior-athlete information.

Security and privacy incidents involving junior-athlete information receive appropriate priority during assessment and response.

11. Artificial Intelligence Processing

Information provided to artificial-intelligence, computer-vision, machine-learning, or infrastructure providers is limited to information reasonably necessary for the applicable processing task.

Core evaluates third-party processors used within its AI systems and seeks contractual protections appropriate to the information processed.

Private identifiable customer video is not authorized for unrelated third-party use merely because the information is transmitted to a processor supporting Core's Services.

12. Production and Development Separation

Core seeks to maintain appropriate separation between production environments and development or testing activities.

Production customer information should not be copied into development environments unless there is a legitimate need and appropriate safeguards are applied.

Where practical, synthetic, anonymized, or de-identified information should be used for development and testing.

13. Secure Software Development

Core incorporates security considerations into the development and maintenance of its applications.

Security practices may include code review, dependency management, access control, change management, testing, secure configuration, vulnerability remediation, logging, and review of material changes affecting sensitive information.

Engineering personnel are expected to avoid introducing credentials, private keys, secrets, or sensitive customer information into public repositories or other unauthorized locations.

14. Vulnerability Management

Core evaluates material vulnerabilities affecting its systems and software and prioritizes remediation based on factors including severity, exploitability, exposure, and potential impact.

Core may use automated tools, infrastructure monitoring, dependency alerts, code review, security testing, third-party reports, and other methods to identify vulnerabilities.

Critical security issues receive prioritized review.

15. Logging and Monitoring

Core maintains logs and monitoring appropriate to operating, troubleshooting, and securing its Services.

Logs may include authentication activity, application events, errors, system activity, infrastructure events, administrative actions, and other security-relevant information.

Access to security and system logs is restricted appropriately.

Core avoids intentionally recording passwords or other unnecessary authentication secrets in application logs.

16. Incident Response

Core maintains processes for identifying, investigating, containing, remediating, documenting, and recovering from security incidents.

Potential incidents are evaluated based on the nature of the event, systems involved, information affected, likelihood of unauthorized access, and potential impact on customers or individuals.

Where required by law or contract, Core will provide appropriate notification following a reportable security breach.

Core may also take steps such as credential resets, token revocation, access suspension, vulnerability remediation, forensic investigation, or customer notification when appropriate.

17. Backups and Availability

Core may maintain backups and recovery mechanisms intended to protect against accidental deletion, infrastructure failures, software failures, or other service disruptions.

Backup information is subject to appropriate access restrictions and is retained according to Core's applicable backup and data-retention practices.

Core tests and adjusts recovery procedures as appropriate for the size, complexity, and operational requirements of the Services.

18. Business Continuity

Core maintains reasonable measures designed to restore important Services following significant infrastructure or operational disruptions.

Business-continuity planning may include redundant cloud infrastructure, backups, recovery procedures, alternate administrative access, vendor support procedures, and incident-management processes as appropriate.

19. Service Providers and Subprocessors

Core uses third-party service providers where necessary to operate its business and Services.

Providers that process sensitive customer information should be evaluated for appropriate security capabilities and be subject to contractual obligations appropriate to their function and access.

Core may use providers for infrastructure, hosting, data storage, authentication, payments, email, support, analytics, video processing, and artificial-intelligence or machine-learning processing.

Core remains responsible for managing its own selection and configuration of such providers as required by applicable agreements and law.

A current list of material subprocessors may be made available to enterprise customers or published by Core.

20. Personnel Security

Core personnel and contractors with access to sensitive systems or customer information are expected to follow confidentiality and security requirements appropriate to their roles.

Access should be provisioned based on business need and removed when employment or engagement ends.

Core may provide security and privacy training appropriate to personnel responsibilities.

21. Physical Security

Core primarily relies on commercial cloud and technology providers for physical hosting infrastructure.

Physical access to data-center infrastructure is therefore subject to the physical security controls maintained by those providers.

Core personnel are expected to protect company devices and prevent unauthorized physical access to systems containing confidential information.

22. Data Retention and Secure Disposal

Core retains customer information for only as long as reasonably necessary to provide the Services, satisfy customer instructions, maintain security and business records, resolve disputes, or meet legal requirements.

When information is no longer required and is eligible for deletion, Core takes reasonable measures to delete or render it inaccessible from active systems.

Information stored within backups may remain until the relevant backup is overwritten or expires according to Core's backup schedule.

Storage media and infrastructure are managed using disposal practices appropriate to the type of system and information involved.

23. Biometric Information

Core does not use biometric identifiers for athlete identification or authentication as part of its standard sports-performance Services unless separately disclosed.

If Core introduces functionality that collects legally regulated biometric identifiers, Core will implement any legally required notice, consent, security, retention, disclosure, and destruction procedures before deploying that functionality.

Core does not sell or profit from biometric identifiers.

24. Confidentiality of Customer Information

Customer information is considered confidential unless the customer intentionally makes it public or the information is otherwise lawfully public.

Personnel may access customer content only when authorized and reasonably necessary for functions such as providing requested services, troubleshooting, support, security investigations, or system maintenance.

25. Customer Responsibilities

Security is a shared responsibility.

Customers are responsible for protecting their usernames and passwords, selecting appropriate organizational administrators, limiting user privileges appropriately, promptly removing users who should no longer have access, keeping contact information current, using supported software and devices, and notifying Core of suspected unauthorized account access.

26. Security Testing and Review

Core periodically reviews security controls and may conduct or commission security testing appropriate to its stage, infrastructure, customer requirements, and risk profile.

Findings that present material security risk are prioritized for remediation.

Core may provide additional security documentation to enterprise customers subject to confidentiality requirements where appropriate.

27. Privacy by Design

Core considers privacy and information-security implications when developing features involving athlete recordings, junior-athlete information, new categories of personal information, artificial-intelligence processing, external integrations, or new service providers.

Where appropriate, Core seeks to minimize the information collected, limit access, reduce retention, and apply protections proportionate to the sensitivity of the information.

28. Legal and Regulatory Compliance

Core maintains its security program with the intention of meeting applicable privacy, security, breach-notification, and children's-data requirements relevant to its Services.

Additional contractual requirements may apply when Core processes information on behalf of particular customers or institutions.

29. Security Questions and Vulnerability Reports

Security questions or good-faith vulnerability reports may be sent to:

Core Sports AI

Security Email: [email protected]

Privacy Email: [email protected]

Reports should contain sufficient information for Core to understand and reproduce the issue but should not include unnecessary personal information or information obtained through unauthorized access.

Core asks security researchers not to access, modify, download, delete, disclose, or disrupt customer information or production systems while investigating a potential vulnerability.

30. Policy Review

Core reviews this Data Security Policy periodically and may update it as technology, business operations, security risks, legal requirements, and industry practices evolve.

Material changes will be reflected by updating the "Last Updated" date and providing additional notice where appropriate.