Trust centre
What an enterprise buyer asks before signing
Selling to a brokerage, a label or a university means clearing a security review before anyone talks about price. This is the page that review starts on. Related: agreements library.
Illustrative only — not legal documents
These pages describe the structure, purpose and clause headings of agreements ShotlistX would put in front of counsel before launch. They are not executed agreements, they create no obligations, they have not been reviewed by a lawyer, and nothing here is legal advice. No clause bodies are published, and no compliance certification is claimed.
Compliance posture
What we hold, and what we don't
No certification badges appear on this site, because none have been earned. A pre-launch company claiming SOC 2 is a claim an enterprise buyer will check in about four minutes — and stating the roadmap honestly reads as maturity rather than as a gap.
SOC 2 Type II
TargetedNot held. An audit would follow the first enterprise contracts — typically a 6–12 month observation window. Shown here as a roadmap item, not a badge.
ISO 27001
TargetedNot held. Sequenced after SOC 2, and only if enterprise demand requires it.
GDPR readiness
TargetedDPA and sub-processor register drafted as part of the enterprise motion. No EU users exist yet, so no processing is occurring.
CPRA readiness
TargetedPrivacy Policy is written to CPRA disclosure structure, including retention by category and Global Privacy Control handling.
COPPA
TargetedRelevant wherever minors appear in youth sports media. The amended Rule reached full compliance in April 2026 and requires separate parental consent for third-party disclosure, retention limits and a written security programme.
PCI DSS
Not applicableWe do not touch card data. Subscription billing would be handled by a PCI-compliant processor; booking payments are settled directly between client and creator.
Security
How the platform is built
Encryption
TLS in transit; encryption at rest for stored media and database contents.
Access control
Least-privilege access, SSO for staff, and audited administrative actions.
Tenant isolation
Organisation data scoped per account, with seat-level permissions inside an org.
Media handling
Portfolio media served from signed URLs so an unlisted portfolio stays unlisted, and delivery links can expire with a licence.
Incident response
Documented severity ladder, named owner, and a customer notification commitment carried in the DPA.
Vulnerability disclosure
A published contact and safe-harbour statement for good-faith researchers.
Sub-processors
Who else touches customer data
A real register names vendors and carries a contractual change-notice obligation. This shows the shape of that register — the categories a platform like this needs — rather than disclosing vendors that aren't yet contracted.
| Category | Purpose | Region |
|---|---|---|
| Cloud hosting provider | Application hosting and static delivery | US |
| Object storage & CDN | Portfolio media storage and egress | US, global edge |
| Payments processor | Subscription billing | US |
| Transactional email | Notifications and account mail | US |
| Error monitoring | Application diagnostics | US |
| Product analytics | Aggregate usage measurement | US |
Diligence
The enterprise kit
What we would hand a procurement team on request, and what is honestly still ahead of us.
- Security overview and architecture summary
- Sub-processor register with change notification
- DPA ready for signature
- Insurance certificates for platform operations
- Penetration test summary — planned, post-launch
- SOC 2 report — planned, see compliance posture above