Official policy / access / confidentiality

Information security &
records.

Available now

The minimum standard for protecting accounts, applicant information, reports, agreements, competitive material, partner data, creative files, and organizational records.

View all resources →

01 / PURPOSE & SCOPE

A focused rule with a defined boundary.

Element Esports grants access because a role needs it—not as a symbol of trust or status. Members must protect organizational accounts and information throughout creation, use, sharing, storage, retention, transfer, and deletion.

This policy applies to email, Discord, social accounts, websites, cloud storage, game and tournament systems, source files, automation tools, devices, documents, applications, reports, agreements, and any copy or export of organizational information.

02 / CORE STANDARDS

The operating baseline.

01

Least privilege

Give each person only the access needed for current duties and review elevated permissions regularly.

02

Strong authentication

Use unique passwords, an approved password manager where practical, and multifactor authentication on sensitive accounts.

03

Approved sharing

Share confidential or personal information only with authorized people through appropriate channels.

04

Data minimization

Collect, copy, export, and retain only what the defined purpose reasonably requires.

05

Recoverability

Use organization-controlled ownership, documented handoffs, backups, and more than one recovery path for critical systems.

06

Rapid reporting

Report suspected compromise, phishing, accidental disclosure, lost devices, excessive access, or destructive errors immediately.

03 / PROCESS

Contain first, then learn.

  1. ReportNotify the designated technology or leadership contact without deleting evidence.
  2. ContainReset credentials, revoke sessions, restrict access, preserve logs, and isolate affected systems when authorized.
  3. AssessIdentify affected accounts, information, people, availability, legal duties, and ongoing risk.
  4. RecoverRestore secure access and service from verified ownership, backups, or trusted records.
  5. NotifyProvide legally or operationally required notice without speculation or unnecessary exposure.
  6. ImproveRecord cause, action, unresolved risk, and preventive changes.

04 / AUTHORITY & LIMITS

Need-to-know is the default.

  • Never share passwords in ordinary chat or reuse personal credentials for organizational accounts.
  • Sensitive exports and local copies must be limited, protected, and deleted when no longer needed.
  • Applicant, minor, guardian, report, health, financial, agreement, and discipline records require heightened access controls.
  • Members may not use confidential information for outside teams, personal leverage, public content, retaliation, or commercial advantage.
  • Offboarding requires prompt account removal, credential rotation where needed, return or deletion of records, and confirmation that critical ownership has transferred.

05 / ACCOUNTABILITY

Document, correct, and improve.

Record retention follows purpose: active operational records while needed; incident, agreement, finance, and governance records according to defined retention targets; unnecessary personal copies should not become permanent archives.

Security mistakes should be reported quickly. Concealment, intentional misuse, unauthorized monitoring, evidence destruction, or reckless credential sharing may require formal review.

Related process

Discipline & Appeals

Protective actions, findings, corrective measures, notice, and appeals follow the organization-wide process.

Read policy →
Safe reporting

Report a concern

Good-faith concerns may be reported without retaliation. Preserve relevant evidence and avoid public escalation that could increase harm.

Open reporting options →