Security & privacy
Analyzing what you received shouldn't force you to hand it over. verdict is designed to see just enough and store as little as possible.
PII redaction
Before showing or summarizing a report, personal data (emails, names, subjects) is masked. The technical indicators needed for analysis are kept, but sensitive content is not exposed. Text extracted from a screenshot goes through the same masking.
Ephemeral processing
The file is analyzed to produce the report and is not kept: neither the raw email body nor the image you uploaded. What persists is the report, with a short retention by default.
Encryption at rest
Reports are stored encrypted with AES-256-GCM. Without the service key, the storage reveals nothing about the analyzed content.
Per-account isolation
Each analysis is tied to whoever uploaded it. A user can only view their own reports; results are not shared across accounts.
Screenshots are read here
Text and QR codes in an image are extracted on our own server, with local OCR. The image is never sent to an AI model or any third party: the only thing that can leave afterwards are the same technical indicators as in an email.
Controlled egress
Enrichment with external services is optional and explicit. In "offline" mode nothing leaves your server; when enabled, only the minimal indicators travel (hashes, IPs, domains), never the full file.
No promises we can't keep
verdict doesn't display certifications or compliance badges it doesn't have. What you see here describes how the system is built, not an external audit.
