LeetQuidity

Trust & Security

Last updated: July 21, 2026

LeetQuidity is used by individual learners and by universities and firms who onboard cohorts of students. This page summarizes how we protect account and learning data. For procurement documents, email support@leetquidity.com.

Data protection

All traffic to LeetQuidity is served over HTTPS/TLS. Data is encrypted in transit and encrypted at rest by our managed database and storage provider.

Payment card data never touches our servers. Checkout and billing are handled by Stripe; we store only Stripe reference identifiers, never card numbers.

We run production error monitoring with personal data collection disabled and session-replay masking enabled, so support diagnostics do not expose learner content.

Access control

Every learner and organization table is protected by database row-level security, so accounts can read and write only their own data. We maintain an automated access-privilege proof harness that verifies these boundaries.

Privileged platform and organization roles are least-privilege and granted through audited, controlled changes — not editable by ordinary accounts.

Sessions are bound to a single active device, and institutional accounts can require SAML single sign-on through their own identity provider.

Your data rights

You can export your account and learning data at any time from your account settings.

You can delete your account and associated personal data; deletion is processed through our managed authentication provider.

We run an automated daily retention job that purges data we no longer need to keep.

Subprocessors

We operate on infrastructure that is independently certified to SOC 2 Type II and ISO/IEC 27001, and we rely on a small, documented set of subprocessors to run the service.

Core providers include Supabase (authentication, database, storage), Vercel (hosting and performance telemetry), Stripe (payments), Sentry (error monitoring), Mux (lesson video), Resend (transactional email), and Google Identity (optional sign-in).

Institutional customers can request our current subprocessor list and Data Processing Addendum (DPA) for review.

Privacy & compliance

We support data-subject rights including access, export, and deletion, and we honor these requests for learners and institutional cohorts alike.

For institutional and enterprise procurement, we can complete security questionnaires and provide a DPA. Contact us to start a vendor security review.

See our Privacy Policy for the full detail of what we collect and why.

Responsible disclosure

If you believe you have found a security vulnerability, please email us before disclosing it publicly. We will acknowledge your report and work with you on a fix.

We will not pursue legal action for good-faith research that respects user privacy, avoids data destruction, and does not degrade the service.

Our machine-readable security contact is published at /.well-known/security.txt.

Related

Read our Privacy Policy and Terms of Service. Institutional buyers can reach the team via the institutional page.