Dead Reckoning Labs
Security
RaceGoat is the race registration platform built by Dead Reckoning Labs. Runners trust us with the details that get them to a start line, so protecting that data is part of the product, not an afterthought. This page explains what we collect, how we secure it, who we rely on, and how we respond when something goes wrong.
1. Data we collect and why
We collect only what a registration and a well-run event actually require:
- Name, email, phone, and address, used for rosters, emergency contact, and bib production.
- Emergency contact details, captured per registration.
- Waiver acceptance, recorded with a timestamp.
- Event-specific fields, configured by each race director for their event.
- Stripe payment intent IDs only. We never store card numbers or full payment details on our servers.
2. How we protect it
- Hosted on Vercel, a SOC 2 provider.
- Neon Postgres, encrypted at rest, a SOC 2 provider.
- Clerk authentication with MFA and SSO support, a SOC 2 provider.
- Stripe webhook signatures verified server-side before we act on any event.
- Sentry error monitoring with PII scrubbed from reports.
- Upstash Redis used for rate limiting and cache only. It holds no durable PII.
3. Payments
All payments run through Stripe, a PCI-DSS Level 1 provider, the highest level of payment security certification. Card data is entered directly with Stripe and never touches our servers.
4. Access
- Staff access requires multi-factor authentication through Clerk.
- Internal access is restricted to the people who need it.
- The database is not publicly reachable.
- Data is scoped per event, so access is limited to the relevant registrations.
5. Subprocessors
We rely on a small set of vetted providers to operate RaceGoat. Each is bound by its own security and compliance program.
| Provider | Purpose | Compliance |
|---|---|---|
| Vercel | Application hosting | SOC 2 |
| Neon | Database (Postgres) | SOC 2 |
| Clerk | Authentication | SOC 2 |
| Stripe | Payments | PCI-DSS Level 1 |
| Resend | SOC 2 | |
| Sentry | Error monitoring | SOC 2 |
| Upstash | Rate limiting and cache | SOC 2 |
6. Incident response
If we confirm a breach that affects registrant data, we notify affected parties within 24 hours.
7. Contact
Security questions and vulnerability reports go to security@deadreckoninglabs.com. We acknowledge every report within 24 hours.
Dead Reckoning Labs, Inc.