One web app that brings every product together
The Verifi Platform is the web app that ties the products together: it brings in detection from the CLI, the Firewall, the Intel corpus, fixes from CodeFix, and remediation from Workflows, then adds the decisioning and policy layer that runs across all of them. Start with intelligence and detection, then add enforcement and automation as you grow. Prefer the named units? See the products.
Intelligence
Powered by Verifi IntelA continuously-built corpus of supply-chain facts: hundreds of thousands of packages, advisories, IOCs, and documented attacks, enriched and connected into a graph. It is also a research engine: it mines public writeups and advisories to connect the dots across seemingly-separate packages (same IOCs, same campaign, same actor) and surface threats early.
Detection
Powered by Verifi CLIA detection harness that scans a package and finds both known issues (matched against authoritative advisory data) and novel ones (malicious behaviour, install-time tricks, dangerous code paths) that no feed has listed yet. The same engine runs in the CLI.
Firewall
Powered by Verifi FirewallA registry firewall that proxies npm, PyPI, and Maven: developers and CI pull vetted artifacts instead of reaching upstream directly. Known-bad never makes it in, and unknowns are quarantined until they clear.
Decisioning
A decision layer that turns raw findings into verdicts that fit your policy and your context, using reachability so you act on what is actually exploitable, not everything that is merely present. Decisioning and policy are the platform's own layer.
Automation
Powered by Verifi WorkflowsWhen something needs doing, Verifi does it: open a fix PR (pulled from CodeFix), block at the proxy, alert the right channel, or run a full incident-response workflow when a bad package is already in your estate.
Adopt it the way that fits
See why teams choose Verifi, what they use it for, and how it connects to the stack you already run.