Enterprise-Grade Security Built for Sports Infrastructure
Sports facilities, tennis academies, and multi-court padel venues handle sensitive member details, payment credentials, biometric access tags, and IoT court automation hardware. At Nevalto, security is not an add-on; it is engineered into every layer of our platform, from client vaults to edge hardware relays.
---
Architecture & Data Sovereignty
All Nevalto production services, member databases, and media repositories are hosted in sovereign European data centres located in Switzerland and the European Union.
| Security Pillar | Specification | Operational Implementation |
|---|---|---|
| Data Residency | Switzerland & EU | Strict compliance with Swiss nDSG and EU GDPR; zero transfers to non-adequate jurisdictions. |
| Encryption at Rest | AES-GCM-256 | Encrypted database storage, encrypted local storage vaults, and hashed audit trails. |
| Encryption in Transit | TLS 1.3 | Strict transport security (HSTS), automated certificate renewal, and PFS cipher suites. |
| Authentication | PBKDF2 & WebAuthn | Progressive lockout protection against brute force, hardware security keys, and secure passcodes. |
| IoT Automation | mTLS & Local Relay | Court lighting relays and door controllers communicate via mutual TLS and isolated local VLAN gateways. |
---
Hardware & IoT Isolation
A major vulnerability in modern sports venues is exposing physical building automation systems (court lights, gate solenoids, HVAC) to public internet attacks. Nevalto enforces strict hardware network segmentation:
- Air-Gapped Local Miniservers: Controllers like Loxone Miniservers and UniFi Access hubs communicate with Nevalto through encrypted outbound-only WebSockets or mTLS endpoints.
- Zero Direct Inbound Ports: Venues do not need to open public firewall ports or configure risky port forwarding rules on their local router.
- Fail-Safe Offline Mode: If a club suffers an ISP outage, local door codes, booked member RFID badges, and scheduled lighting sequences continue functioning autonomously using local controller caches.
---
Access Control & Operator Roles
Nevalto employs granular Role-Based Access Control (RBAC) to ensure that staff and contractors access only the data strictly required for their operational tasks:
- Super Administrator: Club owners and general managers with full access to financial ledgers, audit logs, and hardware configurations.
- Front Desk / Reception: Staff managing daily court check-ins, walk-up court bookings, and retail POS transactions.
- Workshop Technician: Stringers and equipment specialists with access to racquet job queues, string tension history, and reel inventory.
- Coaching Staff: Academy coaches who view student squad rosters and lesson attendance without seeing club accounting ledgers.
---
Privacy by Design & Compliance
- Swiss nDSG & EU GDPR: We act strictly as a data processor for your club. You retain 100% legal ownership of your customer and member databases.
- Zero Third-Party Ad Trackers: We do not inject behavioral ad pixels, tracking scripts, or analytics brokers into member booking portals.
- Instant Data Portability: Venue managers can export all member profiles, transaction journals, and equipment histories as standard JSON or CSV files at any time.
- Right to Be Forgotten: One-click automated anonymization workflow removes all personally identifiable information (PII) upon verified member request while preserving required financial accounting summaries.
---
Continuity & Incident Response
Our infrastructure incorporates automated hourly encrypted snapshots, multi-zone database redundancy, and a tested 99.95% availability SLA. In the unlikely event of an infrastructure anomaly, our engineering team operates 24/7 automated alerting with real-time status updates published at our status dashboard.