Founding access is open for 2026.

Institutional review packet · current posture · August 23, 2026

Follow the data. Protect the athlete.

Use this overview to begin an institutional security, privacy, legal, or procurement review. It separates what EnduraX can substantiate today from the questions that require a scoped answer.

Do not send athlete medical information in an initial inquiry. Review questions can begin with the intended workflow, systems, roles, and required controls.

Open the live Trust Center →Read the privacy policy

Data flow at a glance

A connection is not the same thing as disclosure.

1 · Sources

Athlete check-ins, optional connected providers, and program data agreed for the pilot.

2 · EnduraX

Daily readiness context, athlete controls, and role-bounded coordination workflows.

3 · Services

Only the providers required for hosting, authentication, email, payments, narrow AI, error monitoring, and limited analytics.

4 · People

The athlete and each separately approved role. An administrator does not inherit athlete-health access.

Data inventory and purpose.

This is a readable summary. The privacy policy remains the complete public description of categories, rights, and retention.

Account and profile

Email, display name, date of birth, sex, sport, training level, height, and body weight.

Create the account and personalize applicable product paths.

Retained for the account lifetime; correction, export, and deletion rights apply.

Check-in and readiness

Sleep, fatigue, mood, soreness, stress, training, fueling, optional cycle context, computed scores, and trends.

Build the athlete’s daily read and explain what changed.

The athlete controls relationship sharing. Personal notes remain private.

Connected providers

Supported Oura, WHOOP, Strava, Withings, and Apple Health context when the athlete connects and authorizes a source.

Reduce duplicate entry and add optional context.

Connections are optional and revocable. Raw Apple Health samples remain on device.

Optional fueling

Meal descriptions, optional photos, estimated nutrients, hydration presence, recovery notes, and optional bone-pain check-ins.

Support the separately enabled fueling experience.

The module is opt-in and can be turned off or deleted independently.

Program and team

Agreed roster, role, calendar, training-plan, messaging, and operational context.

Run the exact team workflow defined for the pilot.

Categories, systems, seats, and retention are documented before activation.

Technical and analytics

Security/debugging logs plus allowlisted page paths and content-free product actions.

Secure, operate, and improve the service.

No health data, form contents, session replay, cross-site tracking, or persistent analytics profile.

The athlete controls the relationship.

Team membership establishes a relationship; it does not grant every person the same view. Coach, care, nutrition, performance, and administrative scopes remain separate.

01

Athlete account

The athlete can see their own daily and connected context.

02

Coach relationship

Readiness and training context only inside the sharing scope.

03

Care relationship

Separately approved injury, recovery, clearance, or clinical context.

04

Administrator seat

Membership, roles, schedules, and logistics—not individual readiness or health notes.

Technical safeguards in place now.

Encryption

Data is transmitted over HTTPS/TLS. Data at rest is encrypted within Supabase, and connected-provider access tokens are stored encrypted.

Row-level access

Database row-level security and authenticated server paths are used to restrict account and relationship access.

AI minimization

AI features are narrow and feature-specific. Workout paths exclude direct identifiers; fueling inputs follow separate opt-in and screening controls.

Monitoring and review

Sentry supports technical error monitoring. Sensitive server paths use validation, failure logging, and least-privilege database access.

Service providers and limited purpose.

This table does not mean every provider receives every category. Each service receives only the data required for its stated function.

SupabaseDatabase and authenticationAccount, profile, product, and consented health-related data
VercelApplication hostingRequests and technical hosting data
ResendTransactional emailEmail address and the minimum content required for the message
StripePayment processingBilling identifiers; EnduraX does not store full card details
AnthropicNarrow AI featuresFeature-specific minimized inputs described in the AI disclosure
SentryError monitoringMinimized technical diagnostics; health data and PII are excluded by policy
PostHogLimited cookieless analyticsPage paths and allowlisted content-free actions only

Current compliance posture, plainly stated.

Wellness and performance software

EnduraX does not diagnose, treat, predict injury, prescribe care, or clear participation. Human judgment remains responsible for training and medical decisions.

No unsupported certification claim

EnduraX does not claim SOC 2, HITRUST, ISO 27001, or another certification it has not earned. Current evidence is provided for the exact review date.

HIPAA and FERPA scope must be resolved first

EnduraX is not currently represented as a HIPAA-covered entity. Whether a pilot involves PHI or education records depends on the exact workflow; any BAA, FERPA, or institutional DPA terms must be resolved in writing before activation.

Consumer-health obligations are addressed

The public privacy materials describe applicable consumer-health rights and EnduraX’s stated obligations under the FTC Health Breach Notification Rule.

The contract defines the exact pilot.

Institutional requirements are resolved before institution-scoped data is activated. A public packet can start the review; it does not replace the signed scope.

  • Exact roster, sport, season timing, and pilot duration
  • Every participating seat and whether it is coaching, practitioner, performance, or administrative
  • Included and excluded data categories, systems, and integrations
  • Identity, access, onboarding, offboarding, and support responsibilities
  • Required agreement, DPA, SCC, BAA, residency, insurance, or procurement terms
  • Incident response, continuity, backup and recovery, retention, export, deletion, and pilot-exit requirements

Continue with the source material.