Verisco

Stop the wrong people getting in. Catch the ones who do.

VERISCO builds two security products that cover the whole path an attacker takes. Shield controls the front door. Alertio watches everything behind it.

verisco · shield / sign-in activity
Sign-in activity last 24h · 3 tenants
Evaluated1,284
Stepped up37
Blocked9
MFA cover94%
TimeAccountOriginDeviceDecision
09:52:11n.haddadDZ · Algiers 62step_up
09:48:02s.brahimiDZ · Oran 91allow
09:41:37unknownRU · datacentre block
09:30:15a.mezianeFR · Lyon 88allow
09:22:49k.saidiDZ · Constantine 74allow
Fig. 0.1 — VERISCO Shield — sign-in activity, with the decision trace for a step-up.
3 Applications protected
95 Sign-ins evaluated
94 Policy decisions made
11 Device posture checks

Read from the control plane serving this page within the last 60 seconds. Platform-wide totals only — no tenant, account or location is identifiable here.

One framework, two halves

Most teams buy one product per function, then spend the year making them talk.

We built both sides against the same idea of what an identity is.

Protect · Shield

Who gets in

Identity, device posture, network origin and session state, evaluated before a request reaches your application.

Detect · Alertio

What got through

Every alert scored against a transparent model, and scattered events assembled into kill-chain incidents worth an analyst's time.

Respond · Alertio

What you do next

One-click actions, multi-step playbooks, and signed response scripts deployed to the fleet — carried back to the endpoint.

VERISCO Shield

Identity, without migration.

Adding SSO, MFA and audit logging to an application that already has users normally means rewriting the auth layer or migrating every account. Both are expensive, and both are irreversible.

Shield puts a managed identity layer in front of the application and leaves the user database exactly where it is — verified read-only, against your own MySQL or LDAP.

Take VERISCO away and the application still has all of its users.

How Shield works
verisco · shield / sign-in activity
Sign-in activity last 24h · 3 tenants
Evaluated1,284
Stepped up37
Blocked9
MFA cover94%
TimeAccountOriginDeviceDecision
09:52:11n.haddadDZ · Algiers 62step_up
09:48:02s.brahimiDZ · Oran 91allow
09:41:37unknownRU · datacentre block
09:30:15a.mezianeFR · Lyon 88allow
09:22:49k.saidiDZ · Constantine 74allow
Fig. 1 — Every sign-in carries a decision and the trace that produced it.
VERISCO Alertio

Wazuh detects. Alertio understands.

A detection engine produces thousands of undifferentiated alerts a day, ranked only by a rule severity that knows nothing about which machine was hit, or whether this event is one step in a longer attack.

Alertio adds the layer that decides what deserves a human — a transparent score with the arithmetic shown, and correlation that assembles scattered events into a story.

Seven events, four sensors, two network zones — one incident.

How Alertio works
verisco · alertio / triage queue
Triage queue scored · gate 50
RECON2
CRED2
EXPLOIT1
PRIV1
LATERAL
IMPACT
TimeAlertHostSeverityScore
09:52Domain admin group modifiedDC-01critical94
09:31SQL injection on web tierWEB-02high74
09:20Kerberoast request burstDC-01high71
09:14IMAP brute forceMAIL-01medium58
08:58Port scan from external hostGW-01low31
Fig. 2 — The triage queue, with the kill-chain rail showing how far the intrusion reached.
Built, not sketched

Both products are working systems.

Neither is a prototype or a mockup with a demo mode. Every figure on this site was counted from the source, and both codebases run in CI on every push.

Tested where it matters
108 automated suites across the two products, including a 243-case policy matrix replayed byte-for-byte in CI on every change.
Auditable without trusting us
Shield keeps a hash-chained audit log and ships an offline verifier that imports nothing from the platform, so the other party can check it alone.
Honest about limits
Both products document what they cannot do. Alertio does not respond automatically, and that is a safety decision rather than an omission.

Talk to us about a deployment.

Access is granted by invitation while we are onboarding early clients. Tell us what you run and we will get back to you.