Last Updated: July 1, 2025
At BENCH, your security is our top priority. Whether you're a content creator, team, league, or partner, we understand the importance of keeping your data, media, and payments safe.
We are committed to maintaining a secure environment through rigorous technical safeguards, responsible data practices, and transparent communication.
🔐 Platform Security
We use best-in-class tools and practices to secure BENCH from end to end:
- Encryption in Transit and at Rest: All data is encrypted using HTTPS/TLS during transmission and encrypted at rest in our databases and cloud storage.
- Cloud Infrastructure: BENCH is hosted on secure, industry-leading cloud providers like Vercel & AWS, which maintain rigorous compliance with international security standards (e.g., SOC 2, ISO 27001).
- Web Application Firewalls (WAFs): We proactively monitor traffic and protect against threats like DDoS attacks, injection attempts, and other common exploits.
- Dependency Management: Our software is regularly audited and updated to patch known vulnerabilities across all libraries and packages.
🔐 Account and Access Control
We take strong measures to ensure only authorized users can access sensitive information:
- Role-Based Access: Different user roles (e.g., creator, admin, league manager) have clearly defined permissions to limit exposure of sensitive data.
- Two-Factor Authentication (2FA): Optional 2FA is supported for additional account protection.
- Secure Sessions: Session tokens are protected, scoped, and expire after periods of inactivity.
- Monitoring & Auditing: We maintain logs of key actions and security events, reviewed periodically for anomalies.
🎥 Content Protection
As a platform for sports media monetization, we take content rights seriously:
- Private Video Handling: Uploaded content is stored securely and never made public without your permission.
- Download Restrictions: Content downloads and embeds are restricted unless explicitly enabled by the content owner.
- Watermarking and Licensing: Optional watermarking and licensing metadata can be enabled to deter unauthorized use and protect rights holders.
💸 Payment Security
We do not store your payment card or payout details directly. BENCH partners with trusted third-party processors like Stripe and PayPal for:
- Payouts to creators and leagues
- Subscriber transactions
- Secure financial reporting
All transactions are processed in accordance with PCI-DSS compliance standards.
🛡️ Responsible Disclosure
We encourage ethical security researchers to report any potential vulnerabilities. If you believe you've discovered a security issue or bug, please contact our team at support@jointhebench.com. We review all reports and prioritize fixes based on severity.
📄 Compliance
We are committed to meeting data protection and privacy standards including:
- GDPR (for EU users)
- CCPA (for California residents)
- DMCA (for content takedown and rights enforcement)
You can view our Privacy Policy for more details on data usage and your rights.
📬 Questions or Concerns?
We're here to help. If you have questions about BENCH's security practices, please contact us:
Last updated: July 1, 2025