Veridicus Scan Local Evidence for AI-Bound Content
Download app

Trust model

Local first by default. Explicit when the network is involved.

Veridicus Scan keeps supported imported-content inspection and report generation on device. Network access is purpose-specific: a user-triggered HTTPS destination, a manual signed-rule update check, or StoreKit for entitlement, localized pricing, and purchases. The local foreground boundary also applies to premium MCP sessions while the app is active.

On-device path

Local is the default inspection path.

For supported imports and selected text, the app inspects the content, scores the result, and builds the readable report on device. A link shared into the app enters the separate, user-triggered HTTPS path described below.

Imported files

Supported imports stay in the local inspection lane

TXT/plain, HTML/HTM, SVG, MD/Markdown, PDF, DOCX, XLSX, EML, ICS, JSON, CSV, and PNG/JPG/JPEG/WebP/GIF use the on-device inspection path. URL/WEBLOC files provide a link for the user-triggered HTTPS path rather than uploading the file for remote analysis.

Report generation

Readable evidence is generated from the same local scan

The score, findings, guidance, and coverage notes come from the scan itself, not from a separate remote reporting service.

Layered detection

Rules and semantic review run on device

Deterministic checks work with an on-device semantic layer, including selected Spanish, Chinese, and Arabic patterns rather than a claim of universal language coverage.

When the network is used

Each network path has one disclosed purpose.

Local inspection is not silently converted into a hosted scan. The network is used for a chosen URL destination, a manually requested rule-update check, or StoreKit commerce and entitlement operations.

01

User-provided HTTPS input

The destination is contacted only after the user chooses a specific public HTTPS URL. Strict or lenient redirect handling remains part of the scan boundary and the report records partial or limited coverage.

02

Manual, signed rule-update check

A user can check for verified rules from Settings. The downloaded pack is checked with SHA-256 integrity and an Ed25519 signature before use; scan content is not sent to the update service.

03

StoreKit entitlement and purchases

StoreKit is used for entitlement status, localized pricing, and purchase or restore operations. Those calls do not include scan content, and the site does not hardcode a price that may vary by storefront.

Export boundaries

Sharing should preserve the same restraint as the scan.

Export exists for handoff and review, but the default posture stays conservative. A team can share the outcome without turning the report into an accidental copy of the original suspicious content.

What a teammate sees

  • Risk score, risk band, findings, and guidance
  • Coverage notes if the scan was partial or capped
  • Source context strong enough to review the decision

What stays bounded

  • Evidence snippets are redacted by default
  • Export is deliberate, not automatic
  • Users control whether more evidence is included

Next step

Trust works better when the report surface is just as clear as the scan surface.

Continue into the report page for the output side of the workflow, or jump to the URL explainer if the network boundary is the main concern.