Two decades of email security has been spent on what arrives. Almost nothing has been spent on what leaves. VeridLock exists because that is where the loss actually occurs.
Business email compromise does not arrive with a payload. There is no attachment to detonate, no link to sandbox and no signature to match. An attacker studies a relationship, waits for the moment money or information is expected to move, and sends a message that is plausible in every respect — because it matches the conversation already underway.
Inbound filtering has nothing to grip. The message is well written, the domain resolves, the reply address answers. It is simply a request, and it is answered. The loss happens on the reply, not on the delivery.
VeridLock inverts the assumption. We take it as given that the incoming message may be perfect, and we protect the response instead. Before an answer carrying sensitive information or a payment instruction leaves your organization, the counterparty has to be recognised — and where it is not, a person has to confirm it over a channel the attacker does not control.
A domain with no reputation record has not passed a check — it has failed to be checked. Reporting that as a pass is how confident-looking systems get people hurt. We report unknown as unknown, every time.
Security that interrupts everything gets switched off. We concentrate confirmation on first contact, unrecognised counterparties and changed payment details, and stay out of the way of the correspondence you conduct every day.
A cleared request means cleared to send, not sent. A person presses the button and that press is recorded. Automation decides what needs attention; it does not decide to act on your behalf.
A score without evidence is an opinion. Every VeridLock verdict opens into a check-by-check report naming what ran, what it found, and what could not be determined.
Every record belongs to exactly one organization and every query is scoped to it. Trust lists, scans, audit logs and communication history never cross that boundary.
Three conditions make an organization a target: high transaction values, counterparties who correspond without ever meeting, and time pressure that makes verification feel expensive. Freight forwarding, marine and general insurance, law firms, procurement teams and financial services all have every one of them.
VeridLock is multi-tenant by design and supports head organizations with subsidiaries beneath them, so a group can see its whole tree while each subsidiary keeps its own trust lists, users and records.
Every external dependency in the platform sits behind an interface with a safe default. Verification channels, AI classification, threat feeds, DNS and domain-age lookups and OCR all ship inert: with nothing configured, no external call is made and no data leaves your tenant. Enabling a provider is a configuration change, and paid providers are additionally gated on the subscription that entitles them — so a plan that has not paid for a capability never triggers it.
Outbound
protection first
Multi-tenant
isolated by construction
Full audit
on every decision
Set up your organization in minutes — no inbound migration required.