Built to earn your trust
We take security, privacy, and fairness seriously. Here's an honest look at how we protect every player, organizer, and partner on our platform.
Authentication
Every account is protected by industry-standard OpenID Connect (OIDC) via Keycloak, with optional Steam account linking. Sessions are short-lived, cryptographically signed, and automatically invalidated on logout or suspicious activity.
Keycloak OIDC · Steam bridge · signed JWTs · automatic session revocation →Access Control
Permissions are enforced through a role-based access control model. Organizers, players, and staff each operate within clearly scoped roles — no one can access resources beyond what their role permits.
Role-based permissions · least-privilege enforcement · per-resource scoping →Audit Logs
Every sensitive action — from configuration changes to moderation decisions — is recorded in tamper-evident audit logs with timestamps, actor identity, and affected resource. Logs are retained and available to authorized administrators. Our anti-cheat system goes further still: model version and detection history are published hourly as a cryptographically signed, publicly verifiable transparency log, so independent researchers can audit historical detections without needing platform access.
Immutable event log · actor & timestamp tracking · admin-accessible history · anti-cheat: Ed25519-signed public transparency log →Data Privacy
We collect only what we need to run the platform and never sell your personal data. Project secrets and sensitive configuration values are encrypted at rest using AES-256-GCM. You can request a copy or deletion of your data at any time.
AES-256-GCM encryption at rest · no data selling · data export & deletion on request →Anti-Cheat
Our second-generation anti-cheat system monitors match integrity in real time, flagging anomalous behavior patterns for review. Detected violations trigger automated sanctions and are escalated to our integrity team for final adjudication.
anti-cheat-v2 engine · real-time behavioral analysis · automated sanctions →Identity Verification
High-stakes events and prize-eligible competitions require verified identity. We work with three independent KYC providers to confirm participant eligibility while keeping sensitive documents encrypted and strictly access-controlled.
3 KYC provider integrations · document encryption · eligibility enforcement →Content Moderation
User-generated content is screened by an AI moderation layer that catches policy violations before they reach other users. Flagged content is reviewed by our trust & safety team, and repeat offenders face escalating consequences.
AI moderation pipeline · human review escalation · policy enforcement →Compliance
We maintain alignment with applicable data protection regulations and platform policies. Our internal compliance program is reviewed regularly, and we work proactively with legal counsel to stay current as requirements evolve.
GDPR-aligned data handling · OFAC/AML screening · continuous legal review →Escrow-Protected Payouts
Tournament prize pools are held in custodial escrow until results are final and a dispute window has closed, then released through our payout partner. Payouts above $100 require tax documentation, and cumulative annual payouts above $600 trigger IRS 1099 reporting — all gated on verified identity to keep prize money going to the right person.
Custodial prize-pool escrow · dispute window before release · $100 KYC threshold · $600 1099 threshold →Public Transparency Portal
Sanctions, dispute outcomes, officiating decisions, and rulebook history aren't locked behind a login. Our public transparency portal publishes the sanctions registry, the dispute and appeal ledger, periodic integrity reports, and full rulebook version history — no account required.
Public sanctions registry · dispute & appeal ledger · rulebook version history · periodic integrity reports →Responsible Disclosure
We welcome security researchers who help us keep the platform safe. If you've discovered a vulnerability, please let us know before making it public — we'll work with you to validate and resolve it quickly.
Send a detailed report to our security team at the email below. Include steps to reproduce, potential impact, and any relevant supporting material. We aim to acknowledge all reports within 2 business days and provide a resolution timeline within 10. security@tournamentsuite.com
We recognize meaningful contributions at our discretion. While we don't operate a formal public bug bounty program, researchers who report valid, high-impact findings may be eligible for a reward.
Platform Status
Check the real-time health of our services, review past incident reports, and subscribe to updates so you're never caught off guard by downtime.
View status page →Get support
Have a question or concern that isn't covered here? Our support team is ready to help — choose the path that fits your role.
Organizers
Running a tournament or league? Our organizer support team can help with event setup, participant management, and platform configuration.
Contact organizer support →Players
Questions about your account, a match result, or a moderation decision? Reach out and we'll look into it.
Contact player support →Enterprise
Need a dedicated point of contact, custom SLAs, or a security review for your organization? Talk to our enterprise team.
Talk to enterprise sales →Security is a shared commitment
We're constantly improving how we protect our community. If something doesn't look right — or if you just want to learn more — we're always open to the conversation.
Get in touch