Every protected send runs through five inspection stages before anything leaves your organization. Each stage answers a different question, and each records its answer.
Is this address even what the sender meant to type?
Have we ever done business with this counterparty?
Can this domain physically receive mail, and how long has it existed?
Does this domain defend itself against being spoofed?
Given everything above, what has to happen before this sends?
Four outcomes, each mapping to an explicit request state.
Cleared to send — but only for a counterparty already registered in your trust list. A person still presses send.
Held until a manager authorizes it. Authorization happens in the VeridLock mobile app.
Held until the recipient confirms a one-time code over SMS, WhatsApp or email.
Blocked outright. The message does not become sendable from this request.
A low score alone can never release a message to a counterparty your organization has not registered. Unknown counterparties are forced onto a human path — recipient verification, manager authorization, or both — whatever the engine scored. This is the single rule that stops a quiet message to an unfamiliar address from slipping out.
Start free, then upgrade when you need verification and approvals.