Security & Trust

Your data is safe with us.

Enterprise-grade security infrastructure built from day one. We protect your organization's most sensitive information.

AES-256 Encryption

All sensitive data — phone numbers, passport details, salary information — is encrypted at rest using AES-256-GCM.

GDPR Compliant

Full compliance with European data protection regulations. Data processing agreements available for all organizations.

Role-Based Access Control

Six-level role hierarchy from owner to player. Fine-grained permissions ensure team members only see what they need.

Audit Logging

Every sensitive operation is logged with timestamps and user attribution. Full audit trail for compliance reviews.

Rate Limiting

API endpoints protected with intelligent rate limiting to prevent abuse and ensure platform stability.

HMAC Webhooks

All outgoing webhooks are signed with HMAC-SHA256 for verification. Incoming webhooks validated on every request.

Compliance & Data Governance

We take your data seriously. Here's how we handle it.

Data Residency

Data stored in secure, SOC 2 compliant infrastructure. Available data residency options for enterprise customers.

Data Retention

Clear retention policies with automated data lifecycle management. Export your data at any time.

Parental Consent

Built-in parental consent workflows for players under 18, ensuring compliance with child protection regulations.

Questions about security?

Our team is ready to discuss your security requirements and provide detailed documentation.

Contact Security Team