Security

Last Updated: July 1, 2025

At BENCH, your security is our top priority. Whether you're a content creator, team, league, or partner, we understand the importance of keeping your data, media, and payments safe.

We are committed to maintaining a secure environment through rigorous technical safeguards, responsible data practices, and transparent communication.

🔐 Platform Security

We use best-in-class tools and practices to secure BENCH from end to end:

  • Encryption in Transit and at Rest: All data is encrypted using HTTPS/TLS during transmission and encrypted at rest in our databases and cloud storage.
  • Cloud Infrastructure: BENCH is hosted on secure, industry-leading cloud providers like Vercel & AWS, which maintain rigorous compliance with international security standards (e.g., SOC 2, ISO 27001).
  • Web Application Firewalls (WAFs): We proactively monitor traffic and protect against threats like DDoS attacks, injection attempts, and other common exploits.
  • Dependency Management: Our software is regularly audited and updated to patch known vulnerabilities across all libraries and packages.

🔐 Account and Access Control

We take strong measures to ensure only authorized users can access sensitive information:

  • Role-Based Access: Different user roles (e.g., creator, admin, league manager) have clearly defined permissions to limit exposure of sensitive data.
  • Two-Factor Authentication (2FA): Optional 2FA is supported for additional account protection.
  • Secure Sessions: Session tokens are protected, scoped, and expire after periods of inactivity.
  • Monitoring & Auditing: We maintain logs of key actions and security events, reviewed periodically for anomalies.

🎥 Content Protection

As a platform for sports media monetization, we take content rights seriously:

  • Private Video Handling: Uploaded content is stored securely and never made public without your permission.
  • Download Restrictions: Content downloads and embeds are restricted unless explicitly enabled by the content owner.
  • Watermarking and Licensing: Optional watermarking and licensing metadata can be enabled to deter unauthorized use and protect rights holders.

💸 Payment Security

We do not store your payment card or payout details directly. BENCH partners with trusted third-party processors like Stripe and PayPal for:

  • Payouts to creators and leagues
  • Subscriber transactions
  • Secure financial reporting

All transactions are processed in accordance with PCI-DSS compliance standards.

🛡️ Responsible Disclosure

We encourage ethical security researchers to report any potential vulnerabilities. If you believe you've discovered a security issue or bug, please contact our team at support@jointhebench.com. We review all reports and prioritize fixes based on severity.

📄 Compliance

We are committed to meeting data protection and privacy standards including:

  • GDPR (for EU users)
  • CCPA (for California residents)
  • DMCA (for content takedown and rights enforcement)

You can view our Privacy Policy for more details on data usage and your rights.

📬 Questions or Concerns?

We're here to help. If you have questions about BENCH's security practices, please contact us:

Last updated: July 1, 2025