Security

Security at Fanzava.

Your players give you their data. We treat it accordingly.

This page covers how we protect it, the privacy frameworks we comply with, and what to forward to your IT team.

Two people reviewing a dark monitor in a glass-walled meeting room, a badge reader on the door and the office working on behind them.

Who can see what.

Two layers, sign-in, and isolation.

Sign-in. Email and password, magic link, Google. On Enterprise plans, your players sign in through your own identity provider. Passwords are stored in a form that can't be reversed, even if a database leaked. Two-factor authentication is available to everyone, and required for hub admins on Enterprise plans.

Compatible with your identity provider

  • Okta
  • Microsoft Entra ID
  • Google Workspace

Your hub. Fanzava runs many companies' hubs on the same platform, but your hub's players, scores, leaderboards, and settings live in their own space, completely separated from every other hub. No one in another hub can see your data. Within your hub, group leaderboards are visible only to members of that group.

Read more in our docs: Authentication methods · SSO · Multi-factor authentication · Tenant isolation

Where your data lives.

Fanzava runs in regional cells, each a complete stack with its own database, and your hub's players, picks, scores, leaderboards and settings live in exactly one of them. Australia (Sydney) and the European Union (with its database in Frankfurt) are live today; a United States region is built and not yet serving hubs, so a US hub's data is held in one of the two live regions for now. Enterprise hubs choose their region. Every other hub is assigned one at sign-up, based on where it was created.

Everything moving between your players and Fanzava is encrypted, and everything stored is encrypted, with keys managed by the infrastructure provider in the region your data sits in. Customer-managed encryption keys aren't offered, so if your procurement process needs them, raise it before you sign.

Stripe handles all payments. Fanzava never sees card details.

Read more in our docs: Data residency · Data protection

Compliance you can show your team.

Aligned with the privacy and accessibility frameworks that matter for procurement.

GDPR
UK GDPR
Australian Privacy Act
WCAG 2.1 AA
Framework Status
GDPR Compliant.
UK GDPR Compliant. UK players covered.
Australian Privacy Act Compliant, including the Notifiable Data Breaches scheme.
WCAG 2.1 AA conformance target across customer-facing interfaces.
PCI DSS Out of scope, Stripe handles payments.

Read more in our docs: Compliance posture · DPA & GDPR

Always informed.

What happens in your hub, you see. Admin actions, pool changes, sign-ins, account changes, all recorded in an audit log only you can access. You can export it any time. Enterprise plans can stream events to your existing security monitoring tools.

Security questions or issues go to , acknowledged within 24 hours, with progress updates every two days until resolved.

If a breach affects your players' data, we'll tell you within 72 hours, with the detail you need to notify them yourself.

Read more in our docs: Audit logs · Monitoring, DLP & incident response

Built on infrastructure you trust.

Behind Fanzava are the same providers running banks, governments, and the platforms your team uses every day.

Cloudflare
Stripe
WorkOS
Neon

Read more in our docs: Compliance posture

For your IT or security team.

Built for the IT review. Detailed documentation, organized by topic.

Read the full security documentation

For procurement:

  • Data Processing Agreement. Included in our Terms of Service for paid plans, with Standard Contractual Clauses by default. Separately executable for Enterprise.
  • Sub-processor list. Published at fanzava.com/legal/sub-processors with 30 days' notice of changes.
  • Security questionnaire. Available on request to Enterprise prospects under NDA.
  • Architectural review documentation. Available to Enterprise customers under NDA.

Security disclosures:

Everything else: Contact us

Questions security teams ask.

The short answers. Each one is covered in depth in the security documentation.

Where is our hub's data stored?

In one regional cell: Australia (Sydney) or the European Union (Frankfurt) today. Enterprise hubs choose the region, and the first choice locks, so a later move is an assisted migration on a ticket. Two small central indexes route hostnames and payments to the right cell, and neither holds player personal data.

Can our players sign in through our identity provider?

Yes, on Enterprise. Single sign-on works over SAML or OIDC, with providers such as Okta, Microsoft Entra ID and Google Workspace. Every hub also offers email and password, magic link and Google sign-in.

How are passwords and second factors handled?

Passwords are hashed with Argon2id and never stored, sent or logged in plain text. Authenticator-app two-factor authentication is available on every account, with backup codes for recovery, and it is required by default for hub admins on Enterprise.

Can another organization on Fanzava see our data?

No. Every request carries its hub's identity and every query is filtered to that hub, so one hub's players, scores and settings cannot be read from another. Inside your hub, a group's leaderboard is visible only to that group's members.

How long are audit logs kept?

One year on every paid plan and 90 days on Free. Enterprise keeps two years by default and can configure up to seven. A hub that has been on a paid plan keeps the one-year floor even if it later returns to Free.

Do you handle card details?

No. Stripe processes every payment, so card data never reaches Fanzava and PCI DSS is out of scope for us.

How do we report a vulnerability?

Email security@fanzava.com. Reports are acknowledged within 24 hours, with a status update every 48 hours until the issue is resolved.

What happens if there is a breach?

Affected hub admins are told within 72 hours of a breach being confirmed, with the detail you need to notify your own players and, where it applies, a regulator.

Ready for your security review?

Talk to our enterprise team about SSO configuration, DPAs, data residency, and procurement support.

Talk to our enterprise team