Scores are checked with server timing, score caps, duration checks, and input-count checks in this pre-API version.
Every score requires a one-time session token and deterministic server replay. The claimed browser score is retained only as a tamper signal.
Before scaling, move to server-generated seeds, input replay validation, device/session integrity checks, and a formal fraud review queue.