Vulnerability Disclosure Policy

Effective starting: September 20, 2026

What this Policy covers

League Inc., on behalf of itself and its affiliates, including League Corp. (“us,” “we,” “our,” or “League”) is committed to the security of our platform and the privacy of the people who use it. This Policy applies to any individual or entity (“you”, “your”) who discovers and submits a report to us describing a suspected security vulnerability in one of League’s systems, and explains how to submit your report, what we ask of you, and what you can expect from us in return.

This Policy applies only to the reporting of suspected security vulnerabilities in League systems. It does not apply to:

  • customer data privacy questions or data subject requests, which are governed by the Website Privacy Policy and the Platform Privacy Policy,
  • security testing conducted under a contract with League, including commissioned penetration tests and customer security assessments,
  • any systems League does not operate, including customer-operated environments and third-party websites or services accessible via links from our properties, or
  • reports of suspected fraud, account compromise, or misuse of a member account, which should be directed to help@league.com.

By submitting a report to League, you acknowledge and agree to the terms outlined in this Policy. If you do not agree, please do not submit a report.

Email secteam@league.com.

You may encrypt your report using our PGP key, published at https://league.com/.well-known/LeagueSecteam-VRD-public_key.asc. Our machine-readable security contact information is published at https://league.com/.well-known/security.txt.

For us to accept and assess your report, it must include:

  • a sufficiently detailed description of the issue and why you believe it presents a potential security risk;
  • the affected URL, API endpoint, or area of the product;
  • steps to reproduce the issue, or a proof of concept;
  • the impact you believe an attacker could achieve by exploiting the vulnerability.

We have no obligation to accept reports with missing or incomplete information or that consist only of unvalidated output from an automated scanning tool.

You may choose to submit a report anonymously. If you do, we will not be able to acknowledge your report, request clarification, or keep you informed about the outcome. It is your decision whether to report anonymously or to provide us with contact information.

No. League does not operate a bug bounty program and does not offer monetary compensation, bounties, rewards, or payment of any kind for submitting vulnerability reports to us. We also do not offer non-monetary alternatives such as merchandise or listing on a public recognition page.

This applies to all reports League receives on or after September 20, 2026.

Reports can be submitted in respect of any web services and products operated by League at *.league.com, with the following exclusions:

  • help.league.com
  • go.league.com
  • get.league.com

We will accept reports related to any of the following classes of vulnerability:

  • Cross-site scripting (XSS)
  • Open redirect
  • Cross-site request forgery (CSRF)
  • Command, file, or URL inclusion
  • Authentication and authorization flaws
  • Remote code execution
  • Code or database injection

We do not accept reports concerning any of the following:

  • Account or email enumeration
  • Denial of service and distributed denial of service
  • Intrusion attempts and spam
  • Clickjacking on pages without authentication or sensitive state changes
  • Mixed content warnings
  • Absence of DNSSEC
  • Content spoofing and text injection
  • Timing attacks
  • Social engineering and phishing
  • Insecure cookie attributes on non-sensitive or third-party cookies
  • Issues requiring highly improbable user interaction
  • Issues requiring physical access to a user’s device
  • Public information disclosure
  • Any vulnerability obtained through the compromise of a League member, customer, reseller, or employee account

The following activities are strictly prohibited and fall outside the scope of this Policy:

  • Physical attacks against League personnel, facilities, or offices.
  • Social engineering or phishing directed at League personnel, members, customers, contractors, vendors, or service providers.
  • Knowingly posting, transmitting, uploading, linking to, or sending malware to or from League systems.
  • Probing or scanning that intentionally disrupts or degrades League services.
  • Exfilitation or attempted exfiltration of data.

Should you engage in any conduct that is illegal or prohibited under this Policy, League reserves all right and remedy available to it under applicable law in its sole discretion up to and including reporting you to law enforcement.

You must not:

  1. access, modify, delete, or copy data belonging to any other person or organization including any personally identifiable or protected health information.
  2. exploit any League systems or exceed the minimum activity necessary to demonstrate that a vulnerability exists.
  3. degrade, disrupt, or impair the availability, integrity, or performance of League systems or services.
  4. conduct social engineering, phishing, or physical security testing against League personnel, members, customers, facilities, or vendors.
  5. publicly disclose the vulnerability, or the fact that you reported it to us, without first obtaining our express written authorization to do so.
  6. condition the disclosure of technical details on payment or otherwise attempt to use a report as leverage. All such attempts will be treated as an attempted act of extortion.

Where you make a good faith effort to comply with this Policy and your obligations under it, League will not initiate or support legal action against you.

This policy doesn’t override applicable law or any obligations League has to its customers and partners. If something is unclear, it is your obligation to seek clarification from us before acting.

When you report an issue to us, we will assess the information you provide in order to confirm the existence of the vulnerability. Confirmed vulnerabilities will be recorded and remediated according to priority. Where you have chosen to provide contact information, we will endeavour to keep you informed of progress according to the following timelines:

Acknowledgement of your reportWithin 2 business days
The outcome of our assessmentWithin 5 business days of our receiving sufficient technical detail

These timelines are estimates only and not commitments or guarantees. We will not negotiate specific remediation timelines with you.

If you have questions about this Policy, please contact us through any of the following means:

  • By email at: secteam@league.com
  • By mail at: Product Security League, Inc. 225 King St W, Suite 800 Toronto, Ontario M5V 3M2

To report a suspected vulnerability, please use secteam@league.com rather than the mailing address, so that we can respond within the timeframes stated above.

If we make any changes to this Policy, the updated Policy will be posted online together with all past versions and will include the date on which it becomes effective. Any updated Policy supersedes all past versions. Your submission of a report after the effective date of an updated Policy constitutes your acceptance of its terms.