Security

How Scouting Spy protects your organization's data

Scouting Spy is built for professional and college sports organizations, and the security of your data is foundational to everything we build. This page describes the security practices and controls that are actually in place across the platform today, along with an honest look at the areas we are continuing to strengthen.

Accounts and authentication

Tenant data isolation

Scouting Spy is a multi-tenant platform: every organization's data lives logically separated from every other organization's. This separation is enforced at the data-access layer, not left to individual screens or queries to remember.

Authorization and access control

Secure transport and browser protections

Application hardening

Data protection and backups

API and sync security

Mobile app protection

A modern, maintained stack

Scouting Spy is built on Laravel 13 and PHP 8.5, with security-relevant dependencies kept current. Building on a widely used, actively maintained framework means we inherit a steady stream of security fixes and battle-tested defaults rather than reinventing core protections ourselves.

Areas we are strengthening

Security is ongoing work, and we believe in being candid about what is not yet in place. The following are on our roadmap rather than available today: