What this Policy covers
League Inc., on behalf of itself and its affiliates, including League Corp. (“us,” “we,” “our,” or “League”) is committed to the security of our platform and the privacy of the people who use it. This Policy applies to any individual or entity (“you”, “your”) who discovers and submits a report to us describing a suspected security vulnerability in one of League’s systems, and explains how to submit your report, what we ask of you, and what you can expect from us in return.
Applicability of this Policy
This Policy applies only to the reporting of suspected security vulnerabilities in League systems. It does not apply to:
- customer data privacy questions or data subject requests, which are governed by the Website Privacy Policy and the Platform Privacy Policy,
- security testing conducted under a contract with League, including commissioned penetration tests and customer security assessments,
- any systems League does not operate, including customer-operated environments and third-party websites or services accessible via links from our properties, or
- reports of suspected fraud, account compromise, or misuse of a member account, which should be directed to help@league.com.
By submitting a report to League, you acknowledge and agree to the terms outlined in this Policy. If you do not agree, please do not submit a report.
How to report a vulnerability
Email secteam@league.com.
You may encrypt your report using our PGP key, published at https://league.com/.well-known/LeagueSecteam-VRD-public_key.asc. Our machine-readable security contact information is published at https://league.com/.well-known/security.txt.
What must be included in your report
For us to accept and assess your report, it must include:
- a sufficiently detailed description of the issue and why you believe it presents a potential security risk;
- the affected URL, API endpoint, or area of the product;
- steps to reproduce the issue, or a proof of concept;
- the impact you believe an attacker could achieve by exploiting the vulnerability.
We have no obligation to accept reports with missing or incomplete information or that consist only of unvalidated output from an automated scanning tool.
Anonymous submissions
You may choose to submit a report anonymously. If you do, we will not be able to acknowledge your report, request clarification, or keep you informed about the outcome. It is your decision whether to report anonymously or to provide us with contact information.
Does League pay for vulnerability reports?
No. League does not operate a bug bounty program and does not offer monetary compensation, bounties, rewards, or payment of any kind for submitting vulnerability reports to us. We also do not offer non-monetary alternatives such as merchandise or listing on a public recognition page.
This applies to all reports League receives on or after September 20, 2026.
What domains are in scope?
Reports can be submitted in respect of any web services and products operated by League at *.league.com, with the following exclusions:
- help.league.com
- go.league.com
- get.league.com
What types of vulnerabilities can be reported?
We will accept reports related to any of the following classes of vulnerability:
- Cross-site scripting (XSS)
- Open redirect
- Cross-site request forgery (CSRF)
- Command, file, or URL inclusion
- Authentication and authorization flaws
- Remote code execution
- Code or database injection
We do not accept reports concerning any of the following:
- Account or email enumeration
- Denial of service and distributed denial of service
- Intrusion attempts and spam
- Clickjacking on pages without authentication or sensitive state changes
- Mixed content warnings
- Absence of DNSSEC
- Content spoofing and text injection
- Timing attacks
- Social engineering and phishing
- Insecure cookie attributes on non-sensitive or third-party cookies
- Issues requiring highly improbable user interaction
- Issues requiring physical access to a user’s device
- Public information disclosure
- Any vulnerability obtained through the compromise of a League member, customer, reseller, or employee account
Prohibited conduct
The following activities are strictly prohibited and fall outside the scope of this Policy:
- Physical attacks against League personnel, facilities, or offices.
- Social engineering or phishing directed at League personnel, members, customers, contractors, vendors, or service providers.
- Knowingly posting, transmitting, uploading, linking to, or sending malware to or from League systems.
- Probing or scanning that intentionally disrupts or degrades League services.
- Exfilitation or attempted exfiltration of data.
Should you engage in any conduct that is illegal or prohibited under this Policy, League reserves all right and remedy available to it under applicable law in its sole discretion up to and including reporting you to law enforcement.
Your obligations
You must not:
- access, modify, delete, or copy data belonging to any other person or organization including any personally identifiable or protected health information.
- exploit any League systems or exceed the minimum activity necessary to demonstrate that a vulnerability exists.
- degrade, disrupt, or impair the availability, integrity, or performance of League systems or services.
- conduct social engineering, phishing, or physical security testing against League personnel, members, customers, facilities, or vendors.
- publicly disclose the vulnerability, or the fact that you reported it to us, without first obtaining our express written authorization to do so.
- condition the disclosure of technical details on payment or otherwise attempt to use a report as leverage. All such attempts will be treated as an attempted act of extortion.
Safe Harbour
Where you make a good faith effort to comply with this Policy and your obligations under it, League will not initiate or support legal action against you.
This policy doesn’t override applicable law or any obligations League has to its customers and partners. If something is unclear, it is your obligation to seek clarification from us before acting.
What you can expect from League
When you report an issue to us, we will assess the information you provide in order to confirm the existence of the vulnerability. Confirmed vulnerabilities will be recorded and remediated according to priority. Where you have chosen to provide contact information, we will endeavour to keep you informed of progress according to the following timelines:
| Acknowledgement of your report | Within 2 business days |
| The outcome of our assessment | Within 5 business days of our receiving sufficient technical detail |
These timelines are estimates only and not commitments or guarantees. We will not negotiate specific remediation timelines with you.
Contact us
If you have questions about this Policy, please contact us through any of the following means:
- By email at: secteam@league.com
- By mail at: Product Security League, Inc. 225 King St W, Suite 800 Toronto, Ontario M5V 3M2
To report a suspected vulnerability, please use secteam@league.com rather than the mailing address, so that we can respond within the timeframes stated above.
Changes to this Policy
If we make any changes to this Policy, the updated Policy will be posted online together with all past versions and will include the date on which it becomes effective. Any updated Policy supersedes all past versions. Your submission of a report after the effective date of an updated Policy constitutes your acceptance of its terms.