RecruitMyGame
LoginSign Up

Security Policy

RecruitMyGame, LLC — Vulnerability Disclosure Policy

Reporting a Vulnerability

If you discover a security vulnerability in the RecruitMyGame platform, please report it responsibly. We take all reports seriously and will respond promptly.

Send a detailed report to: security@recruitmygame.com

Please include:

  • A clear description of the vulnerability
  • Steps to reproduce or proof-of-concept (without causing harm)
  • The affected component, URL, or endpoint
  • Potential impact (what data or functionality could be affected)
  • Your contact information for follow-up

Response Timeline

StageTimeline
AcknowledgmentWithin 48 hours
Initial assessmentWithin 5 business days
Critical fix deployedWithin 7 days of confirmation
High fix deployedWithin 30 days of confirmation
Medium/low fix deployedWithin 90 days of confirmation

We will keep you informed throughout the process and credit your contribution if you wish.

Scope

The following are in scope for security research:

  • recruitmygame.com and all subdomains
  • jucoportal.recruitmygame.com and all subdomains
  • The RecruitMyGame API endpoints
  • Authentication and session management flows

The following are out of scope:

  • Denial of Service (DoS/DDoS) attacks
  • Social engineering of RecruitMyGame employees
  • Physical attacks
  • Third-party services (Supabase, Stripe, Vercel, Cloudflare) — report to them directly
  • Issues requiring physical access to a user's device
  • Vulnerabilities in outdated browsers or operating systems

Safe Harbor

We will not take legal action against researchers who:

  • Make a good faith effort to avoid privacy violations and disruption of service
  • Do not access, modify, or delete user data beyond what is needed to confirm the vulnerability
  • Report findings promptly and allow reasonable time for remediation before disclosure
  • Do not use the vulnerability for personal gain or to harm others

Encryption

For sensitive reports, you may encrypt your email using our PGP key (available on request via security@recruitmygame.com).

Automated Security Controls

Every pull request and push to main/staging runs the following automated checks. Findings surface in our CI pipeline and block merges on high/critical findings.

ControlToolCadence
Static analysis (SAST)CodeQLEvery PR + push + weekly
Dependency CVE auditnpm auditEvery PR + push
Secret scanningTruffleHogEvery PR + push
License compliancelicense-checkerEvery PR + push
Dynamic analysis (DAST)OWASP ZAPWeekly + on deploy
RecruitMyGame

Learn about the faces behind Recruit My Game and our mission to help student-athletes achieve their dreams.

Meet Our Team
Evergreen Award 2025

For Athletes

Build Your ProfileSee a Live ProfileMarket Yourself to CoachesGet Your QR Business CardScout a CollegeWho Needs RMG?Pricing

For Coaches & Programs

Find Your Next RecruitGet Your Whole Roster SeenPut Your Program on Film

Playbook

Start Here: Recruiting HubHow Recruiting Really WorksWhy Coach Reviews WinRecruiting InsightsFree Guides & Perks

Company

Contact UsFacebook Community

Partners

NAT Sports DirectoryTosch.aiRMG FoundationSubmit Partner Perk

Legal

Privacy PolicyTerms of ServiceCookie PolicySecurity

Follow Us

© 2026 Recruit My Game, Inc. All rights reserved. Built for student-athletes by student-athlete parents who want to help their kid showcase their complete story. Yes, we are a US-based, family run business!