Security

How DecisionLayer protects the platform and the information parties submit.

Arbitration involves sensitive case materials and personal information. We use administrative, technical, and physical safeguards designed to protect that data against unauthorized access, alteration, disclosure, or destruction. For how we collect and use personal information, see our Privacy Policy.

Security practices

  • Encryption in transit. All connections to DecisionLayer use TLS (HTTPS). Production traffic is also covered by HTTP Strict Transport Security (HSTS).
  • Encryption at rest. Arbitration case data containing personal information is encrypted at rest.
  • Access control. Accounts are authenticated. Users can access only their own cases and materials. Administrative access is restricted.
  • Identity verification. Parties in a case complete identity verification before proceeding.
  • Session and credential security. Session cookies are HttpOnly, use SameSite protections, and are marked Secure in production. Passwords are stored as one-way hashes, never in plaintext.
  • Application protections. We use CSRF protections and browser security headers, including Content Security Policy, clickjacking protection, and MIME-sniffing controls.
  • Least privilege and updates. Access is limited to what is needed to operate the service. We apply security and package updates on a regular cadence.
  • Acceptable use. Technical abuse, unauthorized access attempts, and malware are prohibited under our Acceptable Use Policy.

No method of transmission or storage is completely secure. If you have a security question, contact support@decisionlayer.ai.