VeridLock
Frequently asked questions

The questions we get asked most.

If something here does not answer your question, our team will.

Getting started

No. VeridLock protects the outbound path and does not replace or sit in front of your mail transport. There is no MX change, no inbound migration and no mail routing to reconfigure. You register your organization, add the counterparties you already do business with, and start sending protected messages.

Registering an organization takes a few minutes. The step that determines how quickly the platform becomes quiet is populating the Trust Center — the domains, verified recipients and vendor bank accounts you already deal with. Most organizations seed the counterparties they correspond with weekly on day one and let the rest accumulate as sends are confirmed.

Yes. An organization can be a head organization with subsidiaries beneath it. A head organization administrator sees aggregate activity across the whole tree and can drill into any subsidiary read-only, while each subsidiary keeps its own users, trust lists and records.

Super Admin, Head Organization Admin, Organization Admin, Manager, Employee, Security Officer and Auditor. Permissions differ per role — for example, audit log visibility is tiered so administrators see their organization tree while everyone else sees only their own actions.

Detection & accuracy

Every scan runs the full set of signal services: domain impersonation analysis, full-address impersonation of your verified contacts, content fraud-intent scoring, optional AI classification, financial detail comparison against your vendor baseline, message header tells, URL inspection, attachment analysis, SPF, DKIM and DMARC posture, MX records, domain age, threat intelligence, sensitive data detection and communication history.

Because they are different facts. Privacy-protected registration data, a throttled lookup or a missing DNS record are all cases where a check could not be resolved. Reporting them as a pass would be the single most dangerous thing an assurance tool can do, so VeridLock keeps unknown distinct and treats it as a reason to confirm rather than a reason to relax.

No. Signals are additive and only contribute on a positive detection, so a benign message to a registered counterparty scores as safe. Prompts concentrate on first contact, unrecognised counterparties and changed payment details. Once a recipient has been confirmed and added to your trust list, they stop generating prompts.

Recognised, but never trusted at the domain level. Trusting a public provider wholesale would trust every mailbox on it, including the attacker's. A specific address at a public provider can be registered as a verified recipient, and only that address is treated as trusted.

Full-address analysis. An address within an edit or two of a verified contact — in the local part or the domain — is treated as impersonation and can never resolve as trusted, even on a domain you otherwise trust. The report names the closest verified address so the sender can see exactly what was being imitated.

Verification & approvals

A one-time code is issued to the recipient over a channel separate from email — SMS, WhatsApp or email — and the send only proceeds once that code is returned. Because the confirmation travels outside the email channel, taking over a mailbox or registering a lookalike domain is not enough to satisfy it.

Codes are short-lived by design and expire quickly. An expired code does not release the send and does not fail silently: the request stays visible as awaiting verification, and the sender can reissue a code, escalate for manager authorization, or cancel and return the message to draft.

In the VeridLock mobile application. Authorization is deliberately a separate device and a separate app, so approval cannot be performed from the same compromised workstation that composed the message. The web console shows the approval queue and its outcomes — what has been approved, and what is still awaiting a decision.

No. A cleared request means cleared to send, not sent. A person presses the button and that action is written to the audit trail with a timestamp and an attribution.

Data & privacy

Yes. Every record belongs to exactly one organization and every query is scoped to it. Trust lists, scans, audit logs, approval requests and communication history never cross that boundary. The only global data is the curated platform threat-intelligence list, which contains no customer content.

Only if you enable a provider that requires it, and only for the tenants entitled to that provider. Every external dependency ships inert: with nothing configured, no message content is transmitted anywhere. The AI classifier, threat feeds, domain-age lookups and OCR are each opt-in.

Scans, approval requests and audit logs are retained for the life of your subscription so that investigations and audits have a complete record. Contact us if your regulatory position requires a shorter or longer retention window.

Audit exports are available on the Enterprise plan, alongside compliance reporting and SIEM integration.

Billing

One user, domain risk scoring, content risk scoring, a basic dashboard, community support and a monthly scan allowance. It is intended for an individual to evaluate the engine before bringing colleagues on.

Yes. Billing can be set to monthly or yearly, and yearly billing carries a discount. At checkout you can also choose the number of months you wish to pay for up front, and the total is calculated as you change it.

Card, PayPal, MTN Mobile Money and Orange Money. Mobile money is supported because it is how a large share of our market actually pays.

The subscription page and your dashboard show the expiry state with a renewal prompt as the date approaches and after it passes, so a lapse is always visible rather than silent.

Yes. A new organization is held at the pricing page until a plan is activated. The dashboard becomes available once a plan is chosen and, for paid plans, payment has been accepted.

Still have a question?

Send it to us and a person will answer.