About
Who you would be buying from
Verax is built by Miguel González (S4vz4d), a security engineer and AI red teamer in Madrid.
For three years he designed and hardened security architectures for some of Spain's largest corporations and government departments — deploying and tuning Fortinet, Check Point, Palo Alto and Nozomi across critical infrastructure, and writing the vulnerability-remediation automation around them.
That is the same equipment Verax reads from. The FortiGate parser, the PAN-OS and Zscaler policy generators, the decision to stay agentless and take a log export rather than ask for an install — those are choices made by someone who spent years on the other end of them, being asked to deploy things into production networks.
Since 2024 the work has been offensive testing against AI systems: prompt injection, agent and MCP security, adversarial evaluation of LLMs. Verax exists because that work makes the gap obvious — every company is putting data into these tools, and almost none can say what the vendor does with it afterwards.
What Verax is not, yet
It is a solo project and not yet incorporated. There is no VAT number to invoice against today, no SOC 2 report, no support rota, and no second engineer if I am unavailable. If any of those is a hard requirement for your procurement process, it is not met — and I would rather you read that here than discover it three calls in.
What does exist is the dataset, a citation behind every claim in it, and a monitoring pipeline that has run daily since July 2026.
How the data is built
These are not aspirations. Each is enforced in code, and each exists because it caught something real.
- Nothing is asserted from memory. Every claim is extracted from a document we fetched and stored, and every quote is machine-checked against that stored text. A claim that cannot be supported is dropped rather than softened.
- The quote has to name the company it is cited for. A genuine sentence attached to the wrong entity passes a naive check and is exactly what would poison a regulatory filing.
- Gaps are published, not hidden. The methodology page reports how complete the dataset is, which profiles rest on a single uncorroborated source, and which of our own citation links have gone dead.
- "We could not read it" and "there is nothing there" are different facts. A vendor publishing behind a JavaScript trust portal is reported as unread, never as absent. Only one of those is a question for the vendor.
A trust product that quietly overstates what it knows is worse than no product. See trust for how your own data is handled, and pricing for what Verax is and is not.