Security
Local-first, least privilege
The app keeps basketball data out of the commerce service and treats Google Play as subscription authority.
Designed boundaries
- Basketball rosters, rotations, notes and game events stay on the device.
- Private signing material and service credentials are not embedded as readable app secrets.
- Purchase and Integrity tokens are excluded from logs; durable token identity uses a keyed digest.
- Google Play—not the client or a notification message—is authoritative for subscription state.
- Infrastructure environments, identities and state are separated for staging and production.
Website posture
The static site uses no trackers, ads, cookies, third-party fonts, client-side scripts, account forms or payment flow. Hosting configuration applies strict transport, content security, framing, referrer and permissions headers.
Report a concern
Email support@kobe.net.au with a concise description, affected version or URL, impact and safe reproduction steps.
Do not send an exploit against production, raw player data, purchase or Integrity tokens, passwords, payment data, signing material, keystores or service-account keys. We will arrange a safer channel if sensitive evidence is genuinely required.
No security badge claim
Full Court does not claim an independent security certification or unqualified security guarantee. Security review continues through staged verification and approval gates.