Dead Reckoning Labs
Security
What we collect, how we protect it, which providers we use, and what we do if something goes wrong.
1. Data we collect and why
We collect what a registration and the race need:
- Name, email, phone, and address, used for rosters, emergency contact, and bib production.
- Emergency contact details, captured per registration.
- Waiver acceptance, recorded with a timestamp.
- Event-specific fields, configured by each race director for their event.
- Stripe payment intent IDs only. We never store card numbers or full payment details on our servers.
2. How we protect it
- Hosted on Vercel, a SOC 2 provider.
- Neon Postgres, encrypted at rest, a SOC 2 provider.
- Clerk authentication with MFA and SSO support, a SOC 2 provider.
- Stripe webhook signatures verified server-side before we act on any event.
- Sentry error monitoring with PII scrubbed from reports.
- Upstash Redis used for rate limiting and cache only. It holds no durable PII.
3. Payments
Payments run through Stripe (PCI-DSS Level 1). Card details are entered with Stripe and never reach our servers.
4. Access
- Staff access requires multi-factor authentication through Clerk.
- Internal access is restricted to the people who need it.
- The database is not publicly reachable.
- Data is scoped per event, so access is limited to the relevant registrations.
5. Subprocessors
The providers we use to run RaceGoat:
| Provider | Purpose | Compliance |
|---|---|---|
| Vercel | Application hosting | SOC 2 |
| Neon | Database (Postgres) | SOC 2 |
| Clerk | Authentication | SOC 2 |
| Stripe | Payments | PCI-DSS Level 1 |
| Resend | SOC 2 | |
| Sentry | Error monitoring | SOC 2 |
| Upstash | Rate limiting and cache | SOC 2 |
6. Incident response
If we confirm a breach that affects registrant data, we notify affected parties within 24 hours.
7. Contact
Security questions and vulnerability reports go to security@deadreckoninglabs.com. We acknowledge every report within 24 hours.
Dead Reckoning Labs, Inc.