Local first by default. Explicit when the network is involved.
Veridicus Scan keeps supported imported-content inspection and report generation on device. Network access is purpose-specific:
a user-triggered HTTPS destination, a manual signed-rule update check, or StoreKit for entitlement, localized pricing, and purchases.
The local foreground boundary also applies to premium MCP sessions while the app is active.
For supported imports and selected text, the app inspects the content, scores the result, and builds the readable report
on device. A link shared into the app enters the separate, user-triggered HTTPS path described below.
Imported files
Supported imports stay in the local inspection lane
TXT/plain, HTML/HTM, SVG, MD/Markdown, PDF, DOCX, XLSX, EML, ICS, JSON, CSV, and PNG/JPG/JPEG/WebP/GIF use the on-device inspection path. URL/WEBLOC files provide a link for the user-triggered HTTPS path rather than uploading the file for remote analysis.
Report generation
Readable evidence is generated from the same local scan
The score, findings, guidance, and coverage notes come from the scan itself, not from a separate remote reporting service.
Layered detection
Rules and semantic review run on device
Deterministic checks work with an on-device semantic layer, including selected Spanish, Chinese, and Arabic patterns rather than a claim of universal language coverage.
When the network is used
Each network path has one disclosed purpose.
Local inspection is not silently converted into a hosted scan. The network is used for a chosen URL destination,
a manually requested rule-update check, or StoreKit commerce and entitlement operations.
01
User-provided HTTPS input
The destination is contacted only after the user chooses a specific public HTTPS URL. Strict or lenient redirect handling remains part of the scan boundary and the report records partial or limited coverage.
02
Manual, signed rule-update check
A user can check for verified rules from Settings. The downloaded pack is checked with SHA-256 integrity and an Ed25519 signature before use; scan content is not sent to the update service.
03
StoreKit entitlement and purchases
StoreKit is used for entitlement status, localized pricing, and purchase or restore operations. Those calls do not include scan content, and the site does not hardcode a price that may vary by storefront.
Export boundaries
Sharing should preserve the same restraint as the scan.
Export exists for handoff and review, but the default posture stays conservative. A team can share the outcome
without turning the report into an accidental copy of the original suspicious content.
What a teammate sees
Risk score, risk band, findings, and guidance
Coverage notes if the scan was partial or capped
Source context strong enough to review the decision