Competition Corner takes the security and privacy of your data seriously. While we intentionally limit the technical detail we share publicly — exposing too much about our security practices can give bad actors a roadmap — we want to give you enough confidence to know your data and your athletes' data is in good hands.
Data Center Security
Our infrastructure is hosted across data centers in the United States and Germany, built to handle high-demand events without compromising reliability or security.
Infrastructure scales dynamically to absorb sudden spikes in traffic — no matter how large your event
DDoS mitigation is active across all data centers
We use a suite of industry-leading monitoring tools including Pingdom, PagerDuty, New Relic, and Status.io to proactively detect and respond to any issues, with full transparency to our users via our status page
A documented IT continuity and scaling plan is in place
Data Loss & Corruption Prevention
All databases are isolated and dedicated — multiple layers of logic ensure complete separation between user accounts
Account data is mirrored and backed up off-site on a regular basis
Application Security
Passwords are hashed. Not even Competition Corner staff can view your password. If it's lost, it must be reset — it cannot be retrieved
All data transmitted through the platform, including login pages and API communications, is encrypted via TLS
Login pages and API endpoints are protected against brute force attacks
We conduct regular external security penetration tests throughout the year, covering server-level penetration testing, in-depth application vulnerability assessments, and social engineering drills
Protecting Your Account from Unauthorized Access
Securing our infrastructure is only part of the equation. If your device or credentials are ever compromised, that's a risk to both of us. Here's how we help protect your account even in those scenarios:
We monitor for irregular or suspicious login activity and will automatically suspend accounts that show signs of compromise
Sensitive account changes — such as password updates — trigger immediate email notifications to the account owner
Our systems flag and monitor accounts for signs of abuse, supported by both automated algorithms and a human review layer
Tiered access controls allow you to grant collaborators and volunteers access to only the parts of your account they need — limiting exposure if any individual account is compromised
