Document Overview
LeagueIQ uses administrative, technical, and organizational safeguards designed to protect accounts, league information, connected integrations, uploads, and Service availability. This document describes our security approach; it is not a guarantee that incidents will never occur.
1. Security Principles
Our program is guided by:
- least-privilege access;
- defense in depth;
- encryption where appropriate;
- secure configuration and change management;
- data minimization and limited retention;
- monitoring and incident response;
- provider and dependency review; and
- continuous improvement based on risk.
2. Infrastructure
LeagueIQ may use established cloud, database, authentication, payment, AI, communications, and monitoring providers. We select providers based on functionality, security posture, contractual commitments, and business needs.
Production and development environments should be logically separated. Access to production systems is limited to authorized personnel and services with a business need.
3. Encryption
LeagueIQ uses encrypted network connections for supported production traffic. Sensitive credentials and tokens are stored using provider-supported security controls. Full payment-card numbers are handled by the payment processor rather than stored directly by LeagueIQ.
Encryption reduces risk but does not eliminate it.
4. Authentication and Access Control
We use authentication controls designed to protect accounts and administrative systems. Controls may include password hashing, OAuth, session expiration, role-based access, multi-factor authentication for privileged access, and logging.
Users are responsible for protecting passwords, email accounts, connected accounts, and devices.
Reused or compromised credentials can defeat otherwise reasonable controls.
5. Connected-Account Tokens
OAuth or similar tokens are used only to access the permissions you authorize. We seek to limit scopes to those reasonably necessary for the integration. Tokens may be revoked when you disconnect an account, when a provider invalidates them, or when we detect security risk.
6. Application and Dependency Security
We may use code review, automated scanning, dependency monitoring, configuration review, testing, and remediation processes appropriate to our size and risk. No development process can identify every vulnerability.
7. Logging and Monitoring
We may log authentication events, administrative activity, API requests, errors, security signals, and system performance. Logs help detect abuse, investigate incidents, and maintain reliability. Access to logs is restricted based on role and need.
8. Backups and Resilience
We may use backups, replication, provider resilience, and recovery procedures. Recovery times and data recovery are not guaranteed. Users should retain copies of information that is independently important.
9. Incident Response
Our incident process may include identification, containment, investigation, remediation, recovery, and legally required notification. We may engage service providers, counsel, insurers, or authorities where appropriate.
If we determine that a security incident requires notice, we will provide notice consistent with applicable law and available contact information.
10. Vendor Risk
We evaluate key providers based on the sensitivity of data and service criticality. Contracts may include confidentiality, security, deletion, and incident-notification terms where appropriate. Providers may change as the Service evolves.
11. Privacy by Design
We seek to collect only information reasonably needed for product functionality, security, support, and legal obligations. Private roster and connected-account data is not used to train general-purpose models for unrelated customers without affirmative permission.
12. Certifications and Audit Status
LeagueIQ will not claim a certification, audit report, or regulatory status that it has not obtained. Unless expressly stated in a current written report, the Service should not be represented as SOC 2 certified, ISO 27001 certified, HIPAA compliant, PCI certified, or independently penetration tested.
Payment processing may be provided by a PCI-compliant payment processor, but that does not make every LeagueIQ system independently PCI certified.
13. Vulnerability Disclosure
Good-faith security researchers may report suspected vulnerabilities to security@leagueiq.ai. Include:
- a description of the issue and potential impact;
- affected URL, endpoint, or feature;
- reproduction steps or proof of concept;
- relevant timestamps; and
- a safe method to contact you.
Do not access, modify, retain, or disclose data beyond what is necessary to demonstrate the issue. Do not use denial-of-service, social engineering, phishing, physical intrusion, automated high-volume scanning, or destructive testing. Do not publicly disclose an issue before we have had a reasonable opportunity to investigate and remediate it.
We will not pursue legal action against good-faith research that follows this Policy, avoids privacy harm, and complies with law. This safe-harbor statement does not authorize conduct against third-party systems or excuse violations of law.
14. User Security Responsibilities
Users should:
- use unique passwords and available multi-factor authentication;
- protect email and fantasy-platform accounts;
- review league roles and remove former members;
- disconnect integrations no longer used;
- avoid uploading sensitive personal information;
- verify unexpected invitations or password-reset messages; and
- report suspected compromise promptly.
15. Security Contact
Report security concerns to security@leagueiq.ai. Do not send passwords, access tokens, or full payment-card numbers by email.
Questions about this policy?
Contact our legal team at legal@leagueiq.ai