🛡️ Security & Trust

What actually protects your team's data.

No inflated claims, no certification badges we haven't earned. Here's exactly what RallyText does to protect your team's data — and an honest answer on what we don't have yet.

Try Free for 3 Days Ask a security question
Encryption & access control

Your roster's contact data isn't sitting there in plain text.

Encryption
Per-team phone encryption
Phone numbers are encrypted at rest using Fernet (AES-128-CBC + HMAC-SHA256), with a unique encryption key per team. A database breach exposes ciphertext, not plaintext contact information.
RBAC
Role-based access control
Broadcast messaging is restricted to Head Coaches, Assistant Coaches, and Team Directors — enforced at the API level, not just hidden in the UI. Guardians and athletes can reply but cannot initiate a team-wide broadcast.
MFA
Two-factor authentication
TOTP-based two-factor authentication (authenticator app codes) and WebAuthn/passkey login are both supported. We do not currently offer enterprise SSO/SAML.
Audit Log
Administrative audit trail
Administrative actions on an account — role changes, admin impersonation, roster edits — are logged with actor, action, and timestamp, and are available for review by program directors or league officials.
Transport
TLS everywhere, CSRF protection, rate limiting
All traffic is served over HTTPS. Browser-facing routes are protected against CSRF. Login and API endpoints are rate-limited against brute-force and abuse.
Moderation
On-server content screening
Messages are screened by an AI moderation layer that runs entirely on our own infrastructure — message content is never sent to a third-party cloud service for this purpose.
Data hosting, retention & export

You can get your data out, and old data doesn't linger forever.

All data is hosted on U.S.-based infrastructure. Message logs are retained for 2 years and automatically purged after that; shorter-lived operational data (signup sessions, one-time codes, webhook events) is purged on a much tighter schedule.

Account administrators can export message history, roster, and attendance data as CSV at any time, or request a full account data export.

A2P 10DLC & TCPA compliance

Opt-out and HELP always work. No exceptions, no settings.

RallyText messages are sent through a carrier-registered A2P 10DLC campaign — the compliant pathway for business SMS, distinct from unregistered personal-number group texts that carriers increasingly filter as spam.

STOP and HELP are honored automatically and immediately, enforced at the platform level — this cannot be disabled by a team administrator. Opt-out disclosure text ("Reply STOP to opt out") is shown the first time we message a new recipient, consistent with current carrier guidance, rather than repeated on every single message.

Incident response & risk management

We have a plan before something goes wrong, not just after.

We maintain a written incident response plan covering detection, containment, root-cause investigation, recovery, and customer notification timelines for security incidents. We also maintain a risk register, reviewed quarterly, that is re-verified against the live system at every review rather than left to go stale.

Certifications — the honest answer

What we have, and what we don't.

We do not currently hold SOC 2, NIST, or ISO certification. We'd rather tell you that plainly than have it come up as a surprise during procurement.

What we have done: an internal self-assessment against NIST SP 800-171 control families, and the written incident response plan and risk assessment described above. These are self-assessments, not third-party audits.

If you're evaluating RallyText for a procurement process that requires a security questionnaire, we're happy to fill one out directly — reach out to [email protected].

Frequently asked questions

No. RallyText does not currently hold SOC 2, NIST, or ISO certification. We've completed an internal self-assessment against NIST SP 800-171 control families and maintain a written incident response plan and risk assessment, but these are not third-party audited. We're happy to share detail with prospective customers evaluating us for procurement.
Yes. Phone numbers and other participant contact data are encrypted at rest using Fernet (AES-128-CBC + HMAC-SHA256), with a unique encryption key per team. A database breach would expose ciphertext, not plaintext contact information.
Yes. RallyText supports TOTP-based two-factor authentication (authenticator app codes) and WebAuthn/passkey authentication. We do not currently offer enterprise SSO/SAML.
Data is hosted on U.S.-based infrastructure. Message logs are retained for 2 years and automatically purged after that. Account administrators can export message history, roster, and attendance data as CSV, or request a full data export, at any time.

Questions we haven't answered here?

Email [email protected] — especially if you're filling out a security questionnaire for procurement. We'll answer directly.