JudgmentLab · trust
Security
Last updated: September 2026
Accounts authenticate via Firebase. API routes require verified ID tokens. Entitlements are enforced server-side for paid features and the free sample of sixteen scenarios.
Transport uses HTTPS with HSTS. Responses include standard hardening headers (frame denial, content-type sniffing protection, referrer policy). Sensitive operations are rate-limited.
Initial decisions are immutable after write. Calibration metrics stay provisional until sample sizes support confidence labels.
Report suspected vulnerabilities to security@judgmentlab.app. See also Privacy.