TUF Axiom
Security & Compliance
TUF Axiom was built to the security, privacy, and compliance standards that collegiate and professional athletic programs require. This document summarizes the controls that protect your program's information.
AES-256 at rest, TLS 1.3 in transit. Wearable, body-scan, and health data encrypted end-to-end.
Athletes, coaches, head coaches, and admins see only their role permits. Private wellness data requires explicit athlete opt-in.
Each organization's data is walled at the database layer. No cross-program visibility, querying, or export — ever.
Controls aligned with SOC 2 Trust Service Criteria — access, monitoring, change management, incident response. Formal independent audit in progress; report available on request.
Student-athlete data treated as protected education records. Data minimization by default — only what's needed to optimize performance.
Your institution owns 100% of your data. We never sell, share, or train models on it. Full export and on-demand deletion.
Full audit trail & SSO-ready authentication. Every login, data access, and export is logged. SSO, MFA, and granular permission overrides available for enterprise deployments. Documented breach-response and incident-notification procedures.
Data Ownership Commitment
Your institution owns 100% of your data. TUF Axiom does not sell, share, or use your athletes' information to train models. You may export or permanently delete your data at any time, on request.
© 2026 TUF Axiom · Confidential — for prospect distribution
security@tufaxiom.com · tufaxiom.com