Compliance & Safety Hub
Builtwithchildren'sprivacyatthecenter.
GuardNIL is a family financial-literacy platform — not a bank, not a money transmitter, and not an NIL marketplace. We collect what we need, share with whom we've disclosed, and delete on request. This page documents how, with file-level precision.
The 60-second read
What this page is — and how to use it.
A single source of truth for parents, counsel, partners, and regulators on how GuardNIL handles children's data. Every claim links to a tab below; every tab links to specific files in our codebase.
What we are
A family financial-literacy platform. Parents fund a simulated NIL allowance for their athlete. The athlete completes goals; the parent approves payouts. We are a technology platform — not a bank, not FDIC-insured, not a money transmitter, and not an NIL marketplace.
Who we serve
Families with athletes ages 8–17. Athletes under 13 do not have direct logins — parents enter their data and view their dashboard through the parent account.
The seven invariants we keep
- No PII collected from a child under 13 without verifiable parental consent.
- Every consent grant is logged with IP, user-agent, timestamp, version.
- Every AI text output is screened by our sensitivity classifier before display.
- Coach communications route through parents only.
- Right-to-delete completes within 30 days.
- The audit log is append-only; nobody can alter it.
- Funds never leave Stripe's licensed umbrella.
Where we are today
- Code maturity
- ~93% — playbook §3 implemented
- Lawyer-reviewed
- V1 placeholders, engagement target 2026-06-15
- COPPA Safe Harbor
- Q3 2026 — kidSAFE or ESRB
- SOC 2 Type I
- Pre-Q1 2027
- Designated security personnel
- Galen Oakes — privacy@guardnilu.com
What changed in May 2026
Four independent audit passes (Momus + Metis on Opus, parallel runs) took us from 75% → 84% → 88% → 92% → ~93% over 36 hours. Each pass surfaced specific wiring gaps; each remediation closed them with file:line evidence.
What we don't claim
We don't claim "COPPA-compliant from day one." We don't claim AI moderation we haven't shipped. Our marketing does not promise real money to athletes. Every disclaimer the FTC cited in the NGL settlement informs what we say in public.
What we still need
Counsel-reviewed legal pages, COPPA Safe Harbor membership, cyber insurance, and a third-party background-check vendor for coaches. All are tracked in the Roadmap tab with deadlines and owners.