How we protect your account

Security & privacy

Built for a technical audience, so here is the real detail: exactly how accounts, passwords, and requests are handled, and the precautions baked into the code. No hand-waving, and nothing claimed that isn't actually in place.

Accounts & passwords

Transport & delivery

Request integrity

Browser-hardening headers

Voting, comments, and identity

Data we keep - and don't

Architecture

The site is a statically generated set of pages served as flat files, with a small serverless API for the community features. There's no traditional application server to compromise and the attack surface is deliberately minimal - most of the site is just HTML that can't do anything dangerous.

Reporting a vulnerability

Found something? We want to hear it. Email help@lolclassicwiki.com with the details and we'll get back to you. Please don't publicly disclose an issue until we've had a chance to fix it.

See also the legal & privacy page for data-retention, deletion, and the full disclaimer.

Optional account

Keep your builds with you

Browse, plan, and share without signing in. An account adds voting, comments, private cross-device drafts, and submission tracking.