generated: '2026-08-25' method: probed source: live probes 2026-08-25 name: League vulnerability disclosure provider: League present: false summary: >- NO vulnerability disclosure program was found. This is a genuine gap for a company holding HITRUST, SOC 2 Type 2 and HIPAA obligations across 63M+ members: there is no security.txt, no responsible disclosure page, no published security contact, and no bug bounty on any major platform. security_txt: present: false probed: - {url: 'https://league.com/.well-known/security.txt', status: 403} - {url: 'https://league.com/security.txt', status: 403} - {url: 'https://api.league.com/.well-known/security.txt', status: 404} - {url: 'https://app.league.com/.well-known/security.txt', status: 404} - {url: 'https://help.league.com/.well-known/security.txt', status: 404} note: >- league.com answers 403 for unrouted paths while serving /robots.txt at 200 from the same host, so these are true negatives rather than our client being blocked. disclosure_page: present: false searched: [/security, /responsible-disclosure, /vulnerability-disclosure, trust centre summary page, SafeBase portal landing page] note: >- The league.com/league-trust-centre/ page documents certifications and safeguards but gives no reporting route for a researcher. The SafeBase portal landing page likewise names no security contact. bug_bounty: present: false platforms_checked: [HackerOne, Bugcrowd, Intigriti] note: No program found under the League Inc / league.com brand. recommendation: >- Publishing an RFC 9116 /.well-known/security.txt with a Contact: and Policy: field would be the single cheapest security improvement available to League, and would close the one conspicuous hole in an otherwise strong compliance posture. security_pointer_emitted: false security_pointer_note: >- NO `Security` pointer is wired into apis.yml — the security_disclosure check must reflect a published disclosure route, and League publishes none.