Marketing Hub
AX

TUF Axiom

Security & Compliance

Enterprise-grade protection for your athletes' most sensitive data.

TUF Axiom was built to the security, privacy, and compliance standards that collegiate and professional athletic programs require. This document summarizes the controls that protect your program's information.

SOC 2 AlignedFERPA AlignedHIPAA ReadyAES-256 · TLS 1.3SSO / MFA

Encryption Everywhere

AES-256 at rest, TLS 1.3 in transit. Wearable, body-scan, and health data encrypted end-to-end.

Role-Based Access Control

Athletes, coaches, head coaches, and admins see only their role permits. Private wellness data requires explicit athlete opt-in.

Strict Tenant Isolation

Each organization's data is walled at the database layer. No cross-program visibility, querying, or export — ever.

SOC 2 Aligned

Controls aligned with SOC 2 Trust Service Criteria — access, monitoring, change management, incident response. Formal independent audit in progress; report available on request.

FERPA-Aligned Handling

Student-athlete data treated as protected education records. Data minimization by default — only what's needed to optimize performance.

You Own Your Data

Your institution owns 100% of your data. We never sell, share, or train models on it. Full export and on-demand deletion.

Full audit trail & SSO-ready authentication. Every login, data access, and export is logged. SSO, MFA, and granular permission overrides available for enterprise deployments. Documented breach-response and incident-notification procedures.

Data Ownership Commitment

Your institution owns 100% of your data. TUF Axiom does not sell, share, or use your athletes' information to train models. You may export or permanently delete your data at any time, on request.

© 2026 TUF Axiom · Confidential — for prospect distribution

security@tufaxiom.com · tufaxiom.com