LadderStarLadderStar

Company

Security

Security practices for LadderStar accounts, public profiles, admin operations, billing, messaging, and AI audition features.

Effective date and last updated: May 3, 2026

1. Account protection

LadderStar uses Firebase Authentication for supported sign-in paths. Users are responsible for protecting their email, identity provider accounts, devices, and active sessions.

2. Data access controls

Firestore rules and server routes separate client-owned data from server-owned operational records. Admin and owner authorization must be verified server-side. Wallet balances, wallet transactions, role changes, status changes, and audit logs are designed to be server-owned.

3. Secrets and infrastructure

Production secrets belong in deployment environment settings and must not be committed. Firebase private keys require runtime newline handling. Vercel hosts the application and may provide analytics and performance tooling.

4. Vulnerability reports

Report suspected vulnerabilities, unauthorized access, exposed secrets, account takeover risk, or platform abuse to legal@ladderstar.com. Include steps to reproduce, affected URLs, screenshots or logs where safe, and your contact information.

5. No overclaiming

This page describes current practices at a high level. It does not claim a particular certification, audit, compliance framework, uptime guarantee, or complete immunity from security incidents.

vMay 3, 8:40 PM