About

Enterprise security practice, rebuilt to run on its own

Warden is built by Veritai, founded in 2023. It exists to answer one narrow question: how much of a real security assessment can be done automatically, without pretending it is something it isn't.

Why it exists

Thorough work, priced out of reach of the people now being asked for it

Warden was built inside Veritai by a team whose leadership had each spent twenty-five years on complex online systems for enterprise clients and NGOs — including novel security protocols for organisations that were themselves high-value targets.

That work was thorough, and it was slow. An assessment meant a scoping call, a booked engagement, a fortnight of testing and a report some weeks later. It was priced accordingly, which put it beyond the reach of exactly the organisations who were starting to be asked for one.

Meanwhile the pressure kept rising. Attacks from state-backed actors, supplier audits, insurance requirements and enterprise procurement checklists all now ask the same thing: show us your website is secure.

So the question became how much of that assessment can be done wholly automatically, or with AI assistance — cutting the timeframe, and therefore the cost, by an order of magnitude. The parts that can are now instant and start at $14.99 a month. The parts that cannot are named plainly in every report we issue.

Who we are

The team behind Warden

Five decades of enterprise security practice at the head of the company, and an engineering and research team building the platform that repeats it on a schedule.

Chief Executive Officer

25 years. Complex online systems built for enterprise clients and NGOs, with a focus throughout on online security.

Chief Technology Officer

25 years. The same systems from the engineering side, including novel security protocols developed for high-target clients.

Warden by Veritai

Founded 2023. Warden is Veritai's product, built and maintained by our engineering, research and support teams. We publish roles rather than names — what matters is verifiable in the check list and in what each report admits it cannot see.

Warden by Veritai is a trading style of Dab of Oppo Ltd.

How we work

Three commitments that shape what the product does and does not claim.

Automated where it can be

Thirty-plus checks run without a consultant, a scoping call or a fortnight's wait. Standard checks are read-only. Active testing is authorised by you, per domain, and never runs otherwise.

Built on published standards

Active testing runs on OWASP ZAP. Advisories come from NVD and CVE feeds, reputation from Google Safe Browsing and the Quad9 and Cloudflare resolvers. Nothing rests on a proprietary black box.

Explicit about the limits

Automated black-box testing cannot find business-logic flaws, many blind injection paths, or design-level weaknesses. Every report says so. Absence of findings is not proof that a site is secure, and we would rather you heard that from us.

Warden's own security

We are asking you to trust us with the map of your weak points

A scan report is a sensitive document. Here is how it is handled.

Scan data is encrypted at rest

Findings, evidence snippets and reports are encrypted where they are stored.

We never scan a domain you haven't verified

Every domain requires a DNS record or file upload proving you are authorised before a scan can run against it.

Test-account credentials are encrypted, and deletable

Credentials you add for authenticated scanning are encrypted and can be removed at any time.

Hosted in the EU

Platform and scan data are processed within the European Union.

No scan data shared with third parties

Your findings are not sold, pooled or passed on.

Data deleted on cancellation

Cancel and your reports and scan data are removed.

The full detail is in the privacy notice. Found a vulnerability in Warden itself? Tell us — pick 'Responsible disclosure' on the form.

Judge it on the report, not the pitch

The full sample report needs no account, and it states its own limits.