Reporting a Security Vulnerability
League is committed to the highest security of its platform. Security is central to what we do. If you have discovered a potential or suspected vulnerability in any of our systems, we want to know.
How to reach us
Email secteam@league.com. You can encrypt your report with our PGP key.
Please tell us what the issue is, where you found it, how to reproduce it, and what impact you think it has. Reports that are only automated scanner output, without validation, will not be reviewed.
Before you start, three things to know
We do not pay for vulnerability reports. League does not run a bug bounty. There is no compensation, no reward, and no swag. What we do offer is a commitment to take all reports submitted to us seriously, assess the threat, and undertake timely remediation of confirmed issues.
We take member data seriously. Our platform processes personal user information. While we are interested to know about possible vulnerabilities, we do not tolerate system incursions, attempts to exfiltrate data, or other unlawful activities.
We will not come after you. So long as you are making a good faith effort to comply with our policy, we will not pursue or support legal action against you. The conditions are set out in full in the policy.
What you can expect from us
If you provided us with contact information, we will endeavor to:
- acknowledge your report within 2 business days.
- inform you of the outcome of our assessment within 5 business days of receiving your complete report containing enough technical detail to reproduce the issue.
Read the full policy
All information provided on this page is informational only. The complete terms, including what is in scope, what we ask of you, and our safe harbour commitment, are set out in our Vulnerability Disclosure Policy. Please read it carefully before acting.