Skip to content
Security & trust

Security is not a feature. It is the foundation.

GAMECHANGER360 handles some of the most sensitive information in sport: anonymous reports, evidence, risk assessments and the identities of people who speak up. The platform is built so that trust is enforced by architecture, not policy.
Layered glass panes with signal lines
Principles

Built for security, scale and reliability.

Three layers of assurance run through every product: how the infrastructure is built, how access is controlled and how every action is governed.

Infrastructure

  • Modular multi-product architecture
  • Serverless deployment and edge delivery
  • Distributed databases with organisation-level isolation
  • Automated backups and storage policies

Security

  • Zero-trust architecture
  • End-to-end encryption: TLS in transit, AES-256 at rest
  • Role-based access and row-level security
  • Multi-factor authentication for administrators (TOTP)

Governance

  • Full audit trails
  • Logging across all layers
  • Compliance-ready system design
  • Data residency options agreed per engagement
Security topology

Five layers. Every request checked at each one.

A high-level view of how a request travels from the browser to the data, and what protects it on the way.

  1. Layer 01

    External

    Every request enters through a global edge network before it reaches any application code.

    • User / browser
    • Global content delivery network
    • Web application firewall
    • Bot and abuse filtering
  2. Layer 02

    Network

    Encrypted transport, volumetric protection and hardened name resolution.

    • TLS 1.2+ in transit
    • Volumetric attack protection
    • Hardened DNS
    • Strict transport security
  3. Layer 03

    Application

    Identity is verified on every call, never assumed from a previous one.

    • Managed identity provider
    • Two-factor authentication (TOTP)
    • Verified email addresses
    • Short-lived signed sessions
  4. Layer 04

    Infrastructure

    Isolated compute, secrets scoped per environment and every action logged.

    • Isolated function runtimes
    • Environment-scoped secrets
    • Role-based access
    • Immutable audit logging
  5. Layer 05

    Data

    Isolation and encryption enforced at the row, not left to the application to remember.

    • Row-level security
    • AES-256 encryption at rest
    • Scoped storage policies
    • Automated encrypted backups
AI governance

Intelligence you can audit.

360 Intelligence is the AI core across every product. It is designed to be controllable: scoped, configurable, cited and logged.

01

Organisation-scoped knowledge

Documents and sources are indexed into isolated collections per organisation. One organisation's knowledge never answers another's question.

02

Model choice under your control

The layer is model-agnostic. Which model serves which product is a configuration decision you make and can change, not a dependency you inherit.

03

Citation-tracked answers

Every answer links back to the source passages it was built from, so analysts can verify rather than trust.

04

No training on customer data

Customer data is used only to answer that customer's queries. It is not used to train public models.

05

Key-scoped API access

External access uses keys with credits, rate limits and data-access controls, revocable at any time.

06

Usage logging

Every request, response and configuration change is logged for review.

Reporting confidentiality

Protecting the people who speak up.

360 Report exists for the moment someone decides to say something. Every design decision protects that person first.

  • Anonymous submission by design: no account, no identifying fields required
  • Case reference and secret access code for follow-up without identity
  • Evidence encrypted in transit and at rest, visible only to authorised case managers
  • Two-factor authentication and audit logging for every administrator action
Responsible disclosure

Found something?

If you believe you have found a security vulnerability in a GAMECHANGER360 product or this website, please report it to security@gamechanger360.co.uk. We acknowledge reports within two working days and do not take legal action against good-faith research.

Procurement

Request the full security overview.

Topology, encryption standards, authentication flows, logging and data residency options, shared under NDA as part of your procurement process.