Trust topology
Identity to public receipt
Protected transport
The production customer experience is served over HTTPS.
Account controls
Password, email-code, and supported identity-provider sign-in protect account access.
Verifiable records
Forecast receipts make published forecast payloads independently checkable.
Account security
- Use a unique password of at least eight characters and protect access to your email account.
- Email one-time codes expire and have limited verification attempts.
- Google and Apple sign-in are shown only when their production configuration is available.
- Signing out removes the Veridian session stored by the current browser or app.
Multi-factor authentication is planned.
TOTP enrollment is not available yet. Veridian will not display an enrollment control until the complete server-side challenge flow is ready.
Forecast integrity
Security for a forecasting product includes the integrity of its claims. Veridian records forecast history and exposes signed receipts so a published payload can be checked against its digest and public signing key. A valid signature proves that the payload was issued by Veridian; it does not guarantee that a prediction will be correct.
Operational safeguards
- Customer and operator surfaces are separated, with administrative calls requiring separate authorization.
- Application errors and service health are monitored so degraded data can be identified in the interface.
- Dependencies, builds, and automated tests are reviewed as part of the release process.
- Access to production services and credentials is limited to operational needs.
Report a vulnerability
If you believe you found a security issue, email support@joinveridian.com with “Security” in the subject. Include the affected page, reproduction steps, and impact. Do not access another person’s data, disrupt the service, or test live trading actions.
We will acknowledge good-faith reports and coordinate remediation.
No system is risk-free
No internet service can guarantee absolute security. Keep your device and browser updated, protect your sign-in methods, and contact us immediately if you suspect unauthorized account activity.