Trust centre

What an enterprise buyer asks before signing

Selling to a brokerage, a label or a university means clearing a security review before anyone talks about price. This is the page that review starts on. Related: agreements library.

Illustrative only — not legal documents

These pages describe the structure, purpose and clause headings of agreements ShotlistX would put in front of counsel before launch. They are not executed agreements, they create no obligations, they have not been reviewed by a lawyer, and nothing here is legal advice. No clause bodies are published, and no compliance certification is claimed.

Compliance posture

What we hold, and what we don't

No certification badges appear on this site, because none have been earned. A pre-launch company claiming SOC 2 is a claim an enterprise buyer will check in about four minutes — and stating the roadmap honestly reads as maturity rather than as a gap.

SOC 2 Type II

Targeted

Not held. An audit would follow the first enterprise contracts — typically a 6–12 month observation window. Shown here as a roadmap item, not a badge.

ISO 27001

Targeted

Not held. Sequenced after SOC 2, and only if enterprise demand requires it.

GDPR readiness

Targeted

DPA and sub-processor register drafted as part of the enterprise motion. No EU users exist yet, so no processing is occurring.

CPRA readiness

Targeted

Privacy Policy is written to CPRA disclosure structure, including retention by category and Global Privacy Control handling.

COPPA

Targeted

Relevant wherever minors appear in youth sports media. The amended Rule reached full compliance in April 2026 and requires separate parental consent for third-party disclosure, retention limits and a written security programme.

PCI DSS

Not applicable

We do not touch card data. Subscription billing would be handled by a PCI-compliant processor; booking payments are settled directly between client and creator.

Security

How the platform is built

Encryption

TLS in transit; encryption at rest for stored media and database contents.

Access control

Least-privilege access, SSO for staff, and audited administrative actions.

Tenant isolation

Organisation data scoped per account, with seat-level permissions inside an org.

Media handling

Portfolio media served from signed URLs so an unlisted portfolio stays unlisted, and delivery links can expire with a licence.

Incident response

Documented severity ladder, named owner, and a customer notification commitment carried in the DPA.

Vulnerability disclosure

A published contact and safe-harbour statement for good-faith researchers.

Sub-processors

Who else touches customer data

A real register names vendors and carries a contractual change-notice obligation. This shows the shape of that register — the categories a platform like this needs — rather than disclosing vendors that aren't yet contracted.

CategoryPurposeRegion
Cloud hosting providerApplication hosting and static deliveryUS
Object storage & CDNPortfolio media storage and egressUS, global edge
Payments processorSubscription billingUS
Transactional emailNotifications and account mailUS
Error monitoringApplication diagnosticsUS
Product analyticsAggregate usage measurementUS

Diligence

The enterprise kit

What we would hand a procurement team on request, and what is honestly still ahead of us.

  • Security overview and architecture summary
  • Sub-processor register with change notification
  • DPA ready for signature
  • Insurance certificates for platform operations
  • Penetration test summary — planned, post-launch
  • SOC 2 report — planned, see compliance posture above
Demo — all profiles, jobs and reviews are fictional