Trust

Security & Privacy

Verdict is built with a defense-in-depth approach to data privacy, non-custodial payments, and responsible AI analysis.

Core Security Guarantees

Public Surface Inspection Only

Verdict only accesses and analyzes publicly reachable web pages and documentation. We never request private intranet credentials, internal API keys, or private code repositories.

Non-Custodial Payment Architecture

Verdict never stores user private keys or holds custody of cryptocurrency funds. Human audits require explicit user wallet confirmation in the browser. Agent requests use signed EIP-712 authorizations verified directly on Base.

Server-Side Secret Isolation

All internal LLM API keys, database credentials, and payment facilitator secrets are maintained exclusively in secure server-side environments. No secrets are ever sent to the client.

SSRF & Domain Verification

All submitted URLs are strictly validated against Server-Side Request Forgery (SSRF) filters. Requests to private subnets (10.0.0.0/8, 192.168.0.0/16, 127.0.0.1) and non-HTTP protocols are rejected instantly.

Sanitized Error Boundaries

Internal model failures, database errors, and raw vendor exceptions are stripped and sanitized before reaching public responses, preventing information disclosure.

Relevance Admission Filtering

Acquired web pages must pass explicit entity relevance verification before contributing to audit scoring, preventing injection of malicious or unrelated third-party content.

Audit Data Retention

When an audit finishes, Verdict persists the synthesized report summary and scoring findings in Supabase to enable permanent sharing and grounded follow-up conversation. Raw intermediate scraped HTML and ephemeral planner reasoning are discarded after grading.