Security Overview

This page explains the public-facing security and trust posture of the service so visitors can understand how their data is handled and how the platform is accessed.

Last reviewed 26 July 2026 by the Roster Champion Editorial Team.

Transport security

Public pages and app connections use HTTPS. That keeps requests encrypted while they travel between the browser, the app, and Roster Champion services.

Authentication

Sign-in relies on managed identity flows. The site and app separate public browsing from authenticated actions, which helps keep account operations predictable.

Access control

Team data is shown according to the permissions attached to the account. Shared links and downloads are tied to the relevant subscription and access rules.

How the public site and app are separated

The public website explains the product and publishes guides. The app handles private roster workflows.

Roster Champion separates public content from authenticated product activity. Marketing pages, guides, policy pages, and public support pages are available without sign-in. Private roster data, workspace activity, account details, billing state, and sync operations belong to the app experience and require the relevant account context.

This separation matters for both users and reviewers. Public pages can be crawled and read without exposing private account data. Utility pages such as authentication callbacks, checkout status pages, private workspace views, and redirects are marked noindex so they are not presented as editorial content or advertising inventory.

Operational safeguards

Security is not only a feature; it is part of how the service is operated.

Data handling

Only the data needed to provide the service should be collected. The privacy policy explains the kinds of account, roster, analytics, and billing data that may be processed.

Recovery and resilience

The platform is designed so that maintenance and service updates do not require the entire site to go dark. Public pages remain available even when app state is changing.

Controls visitors can verify

Trust pages should give practical checks, not vague claims.

HTTPS and domain ownership

The public website and app are served over HTTPS on Roster Champion domains. This protects traffic in transit and gives users a consistent place to review the homepage, Topics, privacy policy, cookie policy, terms, security overview, and contact page before opening the app.

Authentication boundaries

Sign-in and account callbacks are separate from public editorial pages. Authentication pages are intentionally thin because their job is to complete a login flow, not to provide content. They are marked noindex and are not treated as AdSense pages.

Least necessary data

Roster Champion should only collect data needed to run the service: account identifiers, roster content, team structure, diagnostics, billing state, and consent choices. The privacy policy explains these categories and the contact route for deletion or access requests.

Operational review

Changes to production deployment scripts include an AWS account check so public website and app deployment stop if credentials do not match the expected Roster Champion account. This reduces the risk of deploying to the wrong cloud account or invalidating the wrong distribution.

What users can do

Security works best when visitors and customers have clear actions.

  • Use a strong password and keep your account details private.
  • Review the privacy policy and terms before activating a subscription.
  • Use the support contact if you think your account needs to be reviewed.
  • Launch the app and check the account settings if you need to confirm an entitlement or plan.

Reporting a security concern

Clear reporting channels help issues reach the right place quickly.

If you believe you have found a security issue, email support@rosterchampion.com with the affected URL, the steps to reproduce, the browser or device used, and whether any account data was exposed. Do not include passwords, payment card details, or private roster data unless support specifically asks for a secure follow-up route.

Privacy questions, billing entitlement issues, and security concerns all use the same monitored inbox. Add "Privacy request", "Billing question", or "Security concern" to the subject so the request can be routed correctly.