Skip to main content

Security and data handling

KoraBridge handles athlete biometric, GPS and wellness data on behalf of clubs, academies and analysts. This page describes what the platform does to protect that data, so you can answer your own security and privacy reviews.

What KoraBridge keeps​

KoraBridge is designed so that the bulk of your athlete data does not stay with us. Pipelines write it into the destination you choose, such as your own warehouse, bucket or database, and you stay in control of it there.

What KoraBridge itself keeps is what it needs to run your pipelines:

  • user accounts and organization settings
  • your source and destination connections, with credentials stored encrypted
  • athlete consent records for sources that need them
  • pipeline, schedule and run history, including usage counts
  • a minimal record, with no personal data, that an organization was deleted

Organization isolation​

Each organization's data is isolated from every other organization's. Access is limited to signed-in members of your organization, and the separation is enforced at more than one level, so a mistake at one level does not expose another organization's data.

Encryption of credentials​

Connector credentials and athlete access tokens are encrypted at rest with a key that is unique to your organization. One organization's key cannot decrypt another's data, and keys can be rotated without losing access to your existing connections.

The API never sends stored credentials back. Connection responses carry settings, not secrets. All traffic between you and KoraBridge is sent over HTTPS.

Sign-in and tokens​

  • Passwords are never stored in readable form. Invited users have no password until they accept their invitation.
  • Invitation and password-reset links are single use and expire. Invitations last 7 days and password resets last 1 hour. Invalid, expired and already used links all show the same generic message.
  • Forgotten passwords. The forgot-password request always answers the same way, whether or not the email address has an account.
  • Sessions. Access tokens are short-lived and renewed with a refresh token. Each refresh token works once. If a used refresh token is presented again, all of that user's sessions are ended. Resetting a password also ends all of the user's sessions.
  • Rate limiting. Sign-in, invitation, password reset and token refresh requests are limited to a few attempts per minute. Excess requests receive 429 Too Many Requests with a Retry-After header.
  • Logging. Passwords, tokens, credentials and request contents are never written to logs.

For connectors that authenticate per athlete (WHOOP, Garmin, Polar and Oura), each athlete approves access to their own data through a consent link. Their tokens are stored encrypted. Revoking an athlete's consent stops future runs from syncing that athlete.

GDPR and POPIA​

For athlete data, the club or organization is the controller and KoraBridge acts as processor.

  • Minimal footprint. Because bulk data lands in your destination, requests to access, export or erase an athlete's data are answered mainly from your own destination. The data KoraBridge holds about an athlete is their consent record, which can be revoked or deleted.
  • Erasing one athlete. Revoke or delete the consent record so future runs stop syncing them. You, as controller, then erase their rows in your own destination.
  • Erasing an organization. Deleting an organization removes its pipelines, runs, schedules, connections, consents, usage records and users. It also destroys the organization's encryption key, so anything stored under it becomes unrecoverable. One record that contains no personal data is kept as evidence of the deletion.
  • Data residency and transfers. For questions about where data is processed or about cross-border transfers, contact us.

What this page does not cover​

Your destination's security, including who can read the tables KoraBridge writes, is yours to manage. Follow the least-privilege guidance on each destination page when you create the access KoraBridge uses.