PinchHitterPoolPinchHitterPool

Security

PinchHitterPool is operated by SoftTelRG LLC. This page describes how we protect accounts and data, and how to report a security problem.

Accounts and sign-in

  • Members sign in with Microsoft, Google, Apple or an email code through our identity provider. PinchHitterPool never stores member passwords.
  • Platform administrators use separate credentials with a mandatory emailed one-time code and lockout after failed attempts.
  • Organizations can be registered only by someone signed in at the organization’s own email domain, who declares they own it or act for its owner.

Data protection

  • All traffic is encrypted in transit (HTTPS with HSTS). The site sends a strict content security policy and blocks framing.
  • Email addresses and phone numbers are encrypted at rest; lookups use one-way hashes.
  • Card details and identity documents are handled by Stripe and never reach our servers.
  • The database runs on Microsoft Azure SQL with Azure’s automated backups.
  • We collect the minimum we need and delete data on the schedule in the Privacy Policy. You can delete your account yourself at any time.

Access control and monitoring

  • Role-based permissions inside every organization: owners decide who can schedule, approve hours, see billing or invite people.
  • Every request is checked on the server, not only in the app. Automated tests try to read and change other organizations’ data before each release.
  • Administrative and organization actions are written to audit logs.
  • Requests are rate-limited, and text-message codes are limited per account, per number and per day to stop abuse.

Reporting a vulnerability

If you believe you have found a security problem, email support@softtelrg.com with “Security report” in the subject, the steps to reproduce it, and what you think the impact is. We will acknowledge your report within three business days and keep you informed while we fix it.

Please test only against your own account, don’t access or change other people’s data, don’t degrade the service for others, and give us reasonable time to fix a problem before you disclose it. We will not pursue good-faith research that follows these rules.

Machine-readable contact: /.well-known/security.txt.