Skip to main content

JudgmentLab · trust

Security

Last updated: September 2026

Accounts authenticate via Firebase. API routes require verified ID tokens. Entitlements are enforced server-side for paid features and the free sample of sixteen scenarios.

Transport uses HTTPS with HSTS. Responses include standard hardening headers (frame denial, content-type sniffing protection, referrer policy). Sensitive operations are rate-limited.

Initial decisions are immutable after write. Calibration metrics stay provisional until sample sizes support confidence labels.

Report suspected vulnerabilities to security@judgmentlab.app. See also Privacy.