Security
Isolation at the database, not in the app layer.
Most league software protects tenants in application code — one bug and you leak. Beleeg enforces tenant boundaries inside Postgres itself, with Row-Level Security policies on every tenant-scoped table.
Tenant model
Postgres RLS
Row-Level Security on every tenant-scoped table.
Transport
TLS 1.2+
HSTS + auto-renewing certificates everywhere.
Audit retention
7 years
Enterprise. Pro 1 year, Free 30 days.
Residency
US + EU
Choose a region per organization. Enterprise.
Pillars
How tenant isolation actually works.
Each pillar maps to a concrete control we can demonstrate on request. The Enterprise security pack includes a runbook for each one.
Tenant isolation at the database
Every tenant-scoped table carries league_id. Postgres Row-Level Security policies enforce isolation at the database, not in app code. Fails closed — an app bug can't break the wall.
Encryption in transit and at rest
TLS 1.2+ everywhere with HSTS and auto-renewing certs. Encrypted-at-rest Postgres storage. Application-level encryption for select fields like payment metadata.
Auth, sessions, scoped API keys
Supabase Auth with email, magic-link, and OAuth. SSO (SAML / OIDC) on Enterprise. API keys are hashed (SHA-256) and scoped per route family, with per-key rate limits.
Audit logs
Every admin mutation writes an audit row with actor, resource, and diff. Retention: 30 days Free, 1 year Pro, 7 years Enterprise. Streamable to your SIEM on Enterprise.
Data residency
US region by default; EU residency available on Enterprise. Tenant data never crosses regions without explicit consent.
Continuously monitored controls
Vanta monitors our security controls around the clock. Enterprise customers can request the current controls report under NDA.
Compliance posture
What we can sign today.
No false claims. Everything on this list is in effect right now — ask us for the paperwork.
GDPR
In effectExport, rectify, and delete requests processed within statutory windows. DPA template available.
CCPA
In effectCalifornia opt-out and access requests handled through the same data-subject pipeline.
PCI scope
Stripe handlesRegistration money settles directly via Stripe Connect. We never see card numbers.
Security controls
MonitoredVanta monitors our controls around the clock. The current controls report is available under NDA on request.
Responsible disclosure
Reporting a vulnerability.
Found something? Email security@beleeg.com. We acknowledge within 24 hours and credit researchers in our changelog. A real human will respond.
Ready when you are
Need the security details?
Enterprise customers can request our security runbook and controls report under NDA. We respond within one business day.