Trust
Security & Privacy
Verdict is built with a defense-in-depth approach to data privacy, non-custodial payments, and responsible AI analysis.
Core Security Guarantees
Public Surface Inspection Only
Verdict only accesses and analyzes publicly reachable web pages and documentation. We never request private intranet credentials, internal API keys, or private code repositories.
Non-Custodial Payment Architecture
Verdict never stores user private keys or holds custody of cryptocurrency funds. Human audits require explicit user wallet confirmation in the browser. Agent requests use signed EIP-712 authorizations verified directly on Base.
Server-Side Secret Isolation
All internal LLM API keys, database credentials, and payment facilitator secrets are maintained exclusively in secure server-side environments. No secrets are ever sent to the client.
SSRF & Domain Verification
All submitted URLs are strictly validated against Server-Side Request Forgery (SSRF) filters. Requests to private subnets (10.0.0.0/8, 192.168.0.0/16, 127.0.0.1) and non-HTTP protocols are rejected instantly.
Sanitized Error Boundaries
Internal model failures, database errors, and raw vendor exceptions are stripped and sanitized before reaching public responses, preventing information disclosure.
Relevance Admission Filtering
Acquired web pages must pass explicit entity relevance verification before contributing to audit scoring, preventing injection of malicious or unrelated third-party content.
Audit Data Retention
When an audit finishes, Verdict persists the synthesized report summary and scoring findings in Supabase to enable permanent sharing and grounded follow-up conversation. Raw intermediate scraped HTML and ephemeral planner reasoning are discarded after grading.