Trust & Security
Last updated: July 21, 2026
LeetQuidity is used by individual learners and by universities and firms who onboard cohorts of students. This page summarizes how we protect account and learning data. For procurement documents, email support@leetquidity.com.
Data protection
All traffic to LeetQuidity is served over HTTPS/TLS. Data is encrypted in transit and encrypted at rest by our managed database and storage provider.
Payment card data never touches our servers. Checkout and billing are handled by Stripe; we store only Stripe reference identifiers, never card numbers.
We run production error monitoring with personal data collection disabled and session-replay masking enabled, so support diagnostics do not expose learner content.
Access control
Every learner and organization table is protected by database row-level security, so accounts can read and write only their own data. We maintain an automated access-privilege proof harness that verifies these boundaries.
Privileged platform and organization roles are least-privilege and granted through audited, controlled changes — not editable by ordinary accounts.
Sessions are bound to a single active device, and institutional accounts can require SAML single sign-on through their own identity provider.
Your data rights
You can export your account and learning data at any time from your account settings.
You can delete your account and associated personal data; deletion is processed through our managed authentication provider.
We run an automated daily retention job that purges data we no longer need to keep.
Subprocessors
We operate on infrastructure that is independently certified to SOC 2 Type II and ISO/IEC 27001, and we rely on a small, documented set of subprocessors to run the service.
Core providers include Supabase (authentication, database, storage), Vercel (hosting and performance telemetry), Stripe (payments), Sentry (error monitoring), Mux (lesson video), Resend (transactional email), and Google Identity (optional sign-in).
Institutional customers can request our current subprocessor list and Data Processing Addendum (DPA) for review.
Privacy & compliance
We support data-subject rights including access, export, and deletion, and we honor these requests for learners and institutional cohorts alike.
For institutional and enterprise procurement, we can complete security questionnaires and provide a DPA. Contact us to start a vendor security review.
See our Privacy Policy for the full detail of what we collect and why.
Responsible disclosure
If you believe you have found a security vulnerability, please email us before disclosing it publicly. We will acknowledge your report and work with you on a fix.
We will not pursue legal action for good-faith research that respects user privacy, avoids data destruction, and does not degrade the service.
Our machine-readable security contact is published at /.well-known/security.txt.
Related
Read our Privacy Policy and Terms of Service. Institutional buyers can reach the team via the institutional page.