Security Policy
Last Updated: February 2, 2026
1. Our Security Commitment
Security is a fundamental part of the beIN90 platform.
beIN90 provides cloud-based software for football clubs, academies and sports organizations that may process sensitive operational, personal, financial, player, employee, performance, video and organizational information.
We design our Services with the objective of protecting Customer Data against unauthorized access, unauthorized disclosure, alteration, loss and destruction.
Security is treated as an ongoing process rather than a single product, certification or technical control.
2. Customer Data Isolation
beIN90 operates as a multi-organization SaaS platform.
Customer organizations are logically separated within the application.
Authorization decisions are associated with the authenticated user, organization membership, role, permissions and requested resource.
A user authorized for Organization A is not authorized to access Customer Data belonging to Organization B.
Organization boundaries are treated as a core security requirement across application functionality.
This principle applies, as applicable, to:
- player records;
- staff records;
- teams;
- attendance;
- training information;
- documents;
- financial records;
- inventory;
- facilities;
- videos;
- images;
- reports;
- analytics;
- AI functionality;
- exports;
- notifications;
- integrations.
3. Authentication
beIN90 uses authentication controls designed to ensure that users can access only accounts and organizations for which they are authorized.
Security controls may include:
- password-based authentication;
- protected credential storage;
- session management;
- account verification;
- authentication controls;
- password reset controls;
- session expiration;
- administrative access controls.
Where available, additional authentication mechanisms may be enabled according to the customer's subscription and configuration.
4. Authorization and Role-Based Access
Authentication alone does not grant access to Customer Data.
beIN90 uses authorization mechanisms to determine what an authenticated user is permitted to access or perform.
Permissions may be based on:
- organization;
- role;
- module;
- resource;
- action;
- administrative privileges.
Examples of permissions may include:
- viewing;
- creating;
- editing;
- deleting;
- exporting;
- approving;
- managing users;
- managing financial information;
- managing documents.
Authorization is intended to follow the principle of least privilege.
5. Administrative Access
Administrative access to production systems is restricted to authorized personnel who require such access for legitimate business or technical purposes.
Administrative access may be subject to:
- authentication controls;
- access approval;
- least-privilege principles;
- logging;
- monitoring;
- periodic review.
beIN90 does not provide employees with unrestricted access to all customer information merely because they are employees.
Where operational access is required, it should be limited to the minimum scope reasonably necessary to perform the relevant task.
6. Encryption
beIN90 uses encryption and secure communication mechanisms appropriate to the systems and data involved.
Data transmitted between users and beIN90 services should be protected using encrypted communication protocols such as HTTPS/TLS.
Where supported by the underlying infrastructure, sensitive information stored in databases, storage systems and backups may be protected through encryption at rest.
Specific cryptographic technologies may change as the platform evolves.
7. Infrastructure Security
beIN90 uses cloud and infrastructure services to operate its platform.
Infrastructure security may include:
- network access controls;
- firewall controls;
- restricted administrative access;
- operating-system security;
- secure configuration;
- patch management;
- monitoring;
- backups;
- infrastructure logging;
- controlled deployment processes.
Third-party infrastructure providers are selected based on business, technical and security requirements appropriate to the services they provide.
8. Application Security
beIN90 follows secure software development principles intended to reduce application security risks.
Security considerations may include:
- server-side authorization;
- input validation;
- authentication controls;
- session security;
- access control;
- secure API design;
- dependency management;
- secrets management;
- logging;
- error handling;
- secure deployment practices.
Security requirements are considered during feature development and system changes.
9. API Security
beIN90 APIs are designed to enforce authentication and authorization controls before protected resources are returned or modified.
API security controls may include:
- authenticated requests;
- authorization checks;
- organization-level access checks;
- input validation;
- rate limiting where appropriate;
- request logging;
- protection of sensitive endpoints.
A successful authentication event does not by itself authorize access to resources belonging to another organization.
10. Data Access Controls
Access to Customer Data is controlled according to authorization requirements.
beIN90 seeks to prevent unauthorized access through:
- organization boundaries;
- role-based permissions;
- administrative access restrictions;
- authentication;
- audit logging;
- operational controls.
Access rights should be removed or modified when personnel no longer require them.
11. Logging and Auditability
beIN90 maintains logs and security events appropriate to the operation and security of the Services.
Depending on the system, logs may include:
- authentication events;
- authorization events;
- administrative actions;
- security events;
- system errors;
- service activity;
- changes to important resources.
Logs are used for troubleshooting, security monitoring, incident investigation and operational accountability.
Security logs may be retained for a period determined by operational, legal and security requirements.
12. Monitoring
beIN90 monitors its infrastructure and Services to identify:
- service failures;
- abnormal behavior;
- security events;
- infrastructure problems;
- availability issues.
Monitoring and alerting are continuously improved as the platform evolves.
13. Vulnerability Management
beIN90 seeks to identify and address vulnerabilities affecting its application, dependencies and infrastructure.
Security activities may include:
- dependency updates;
- vulnerability scanning;
- security reviews;
- patch management;
- code review;
- infrastructure updates;
- penetration testing where appropriate.
The severity and remediation priority of a vulnerability may depend on its potential impact, exploitability and affected systems.
14. Secrets and Credentials
Production credentials, API keys, access tokens and other secrets should not be stored in source-code repositories.
Secrets are managed using controlled mechanisms appropriate to the environment.
Access to secrets is restricted according to operational requirements.
15. Backups and Recovery
beIN90 maintains backup and recovery mechanisms designed to support restoration of Services and Customer Data following technical or operational incidents.
Backup procedures may include:
- automated backups;
- backup retention;
- restricted backup access;
- monitoring;
- restoration procedures;
- disaster-recovery procedures.
Backups may remain for a limited period after Customer Data is removed from production systems.
16. Availability and Resilience
beIN90 seeks to maintain the availability and resilience of its Services through:
- infrastructure monitoring;
- backups;
- fault recovery;
- controlled deployments;
- incident response;
- operational monitoring.
Specific uptime commitments, recovery time objectives and recovery point objectives may be defined in applicable customer agreements or Service Level Agreements.
17. Secure Development Lifecycle
Security is incorporated into software development processes where appropriate.
Development controls may include:
- source-code access control;
- code review;
- dependency management;
- environment separation;
- controlled deployments;
- testing;
- security review of material changes.
Development and production environments should be appropriately separated.
18. Third-Party Providers
beIN90 may rely on specialized providers for:
- cloud infrastructure;
- storage;
- email;
- payments;
- monitoring;
- analytics;
- security;
- AI;
- customer support.
Third-party providers that process Customer Data on behalf of beIN90 are evaluated and governed according to applicable contractual and security requirements.
19. AI Security and Customer Data
AI functionality may process Customer Data when necessary to provide a feature requested by a customer.
beIN90's security and privacy principles apply to AI-related processing.
Customer Data is not intentionally exposed to another customer through AI features.
beIN90 does not intentionally use one customer's confidential information to generate customer-specific information for another customer.
Where third-party AI providers are used, appropriate technical and contractual controls should be applied.
20. Video and Sports Analytics Security
Video and sports-analysis systems may process large files and derived information.
Security controls may include:
- authenticated upload;
- organization-level access control;
- protected storage;
- restricted download;
- access logging;
- controlled processing;
- deletion according to applicable retention rules.
Video-derived information is treated as Customer Data when submitted or generated on behalf of a customer organization.
21. Incident Response
beIN90 maintains procedures for responding to security incidents.
Incident response may include:
- detection;
- initial assessment;
- containment;
- investigation;
- remediation;
- recovery;
- notification where required;
- post-incident review.
Where a security incident involving Customer Data triggers a contractual or legal notification requirement, beIN90 will provide notification in accordance with applicable law and the applicable customer agreement.
22. Security Breach Notification
If beIN90 determines that a confirmed security incident has affected Customer Data and notification is legally or contractually required, beIN90 will notify the appropriate customer contact without undue delay in accordance with the applicable requirements.
Notifications may include available information regarding:
- the nature of the incident;
- affected systems;
- affected data;
- known or expected impact;
- containment actions;
- remediation actions;
- recommended customer actions.
23. Employee Security
Personnel with access to systems or Customer Data are expected to follow applicable security and confidentiality requirements.
Security practices may include:
- confidentiality obligations;
- access controls;
- onboarding and offboarding procedures;
- security awareness;
- least-privilege access;
- access reviews.
24. Confidentiality
beIN90 treats Customer Data as confidential information.
beIN90 does not sell Customer Data to other football clubs, academies or organizations.
Customer Data is not intentionally provided to another customer for that customer's independent commercial use.
25. Security Testing
beIN90 intends to continuously improve its security program through appropriate testing and assessment.
Testing may include:
- vulnerability assessments;
- dependency scanning;
- security reviews;
- penetration testing;
- access reviews;
- configuration reviews;
- backup restoration tests.
The frequency and scope of testing may depend on risk and the maturity of the applicable system.
26. Security Certifications
beIN90 will publish applicable independent certifications or audit reports when they have been formally obtained.
Examples may include:
- ISO/IEC 27001;
- SOC 2;
- ISO/IEC 27701;
- other applicable certifications or independent assessments.
Until such certifications are formally obtained, beIN90 does not represent itself as certified.
27. Customer Security Responsibilities
Security is a shared responsibility.
Customers are responsible for:
- protecting account credentials;
- assigning appropriate user roles;
- removing users who no longer require access;
- configuring permissions appropriately;
- protecting administrator accounts;
- uploading information only when legally permitted;
- obtaining required permissions for player, parent, employee, image and video data;
- promptly reporting suspected security incidents.
28. Responsible Disclosure
Security researchers who believe they have identified a vulnerability in beIN90 are encouraged to report it responsibly.
Reports should include:
- affected service;
- description of the issue;
- steps required to reproduce it;
- potential impact;
- relevant evidence.
Security reports should be sent to: [email protected]
Please do not access, modify, delete or disclose another customer's information while investigating a suspected vulnerability.
29. Continuous Improvement
Security is continuously reviewed as the beIN90 platform, infrastructure, customer requirements and threat landscape evolve.
Controls described in this Security Policy may be updated as beIN90 improves its security program.
30. Contact
For security-related questions or vulnerability reports:
beIN90 Security Team
Email: [email protected]
Security Policy Version: 1.0
Last Updated: February 2, 2026
