Security Practices
Sports Med Flow Pro is built to support Athletic Trainers who handle protected health information and student education records. These are the safeguards in the product today. AI features that would send clinical text to a model provider stay off until a platform administrator turns them on after processor agreements are on file. Software controls are not a HIPAA or FERPA certification.
Workspace isolation
Every trainer account has its own workspace. Records are filtered at the database level, not just hidden in the interface, so another account cannot reach them even by guessing an address. View-only seats cannot change student records.
Signed notes stay with their author
Signed clinical notes and their PDFs are readable only by the trainer who created and signed them. District administrators manage seats and billing and cannot open medical records.
Permanent access log
Opening a profile, downloading a signed note, exporting a treatment log, amending a visit, and signing in are written to a log that cannot be edited or deleted by any account.
Private file storage
Uploaded documents, signed PDFs, and credential files live in private storage and are opened through links that expire in about two minutes.
Session safeguards
Staff sessions end after ten minutes of inactivity. AT Sidekick parks the trainer session in an http-only cookie so a shared tablet never holds a live clinical login. A 4-digit exit code is required to return to staff screens, and copied sign-in tokens stop working when the kiosk is locked.
On-device facial matching
Kiosk face check-in matches on the device and stores only a numeric signature for the assigned campus. No face photographs are ever kept.
Reporting a vulnerability
If you believe you have found a security issue, contact your workspace owner with the details and steps to reproduce it, and please do not access records that are not yours while investigating.
