VeriTrust

VeriTrust provides evidence-aware email investigation, URL intelligence, and a correlation Gateway. The email workflow distinguishes pasted text, raw .eml evidence, and trusted receiver evidence so unavailable forensic signals are not presented as verified facts.

VeriTrust email investigation guide.

VeriTrust investigates suspicious email content and raw email evidence, verifies available sender-authentication signals, compares sender identities, evaluates embedded URLs, traces observable delivery infrastructure, and correlates the available evidence under policy. Results preserve explicit limitations instead of turning missing checks into a safe result.

Use each result as decision support. It can prioritize a manual review, but it cannot establish authenticity, malicious intent, legal responsibility, or safety.

Core Investigation Workflows

  • Investigate suspicious emails before employees click links, reply, send money, or disclose credentials.
  • Use original .eml evidence when sender authentication, attachment metadata, and delivery-route context matter.
  • Correlate message, URL, identity, and infrastructure evidence for a repeatable analyst review.
  • Preserve report IDs, limitations, evidence completeness, and technical provenance for case notes and escalation.

Email Threat & Forensic Investigation

Email Investigation accepts pasted message content or original email evidence. It combines MailGuard model evidence, deterministic social-engineering indicators, available authentication verification, sender-identity relationships, extracted URLs, attachment metadata, and observable relay infrastructure.

  • Include sender text, link text, and call-to-action wording when available.
  • Avoid submitting passwords, one-time codes, payment details, or private customer records.
  • Treat urgent payment requests, credential prompts, and unusual login links as higher priority for manual review.
  • Use the result to decide whether to block, escalate, educate the user, or request more information.

Web CLI

The authenticated VeriTrust Web CLI provides an allowlisted browser shell for email, link, and correlation workflows. It is a convenience interface, not an operating-system shell.

  • Use scan gateway with --text, repeatable --url flags, and an optional attachment to use the evidence-correlation Gateway.
  • Add --json for structured output, --no-wait for asynchronous gateway submission, and use gateway get <scan-id> to retrieve it later.
  • Use status, models, and history --limit 10 to inspect the active workspace and supported engines.

The Web CLI is not an operating-system shell. It does not evaluate scripts or arbitrary commands, and local files can be selected only through the browser's protected file picker.

Privacy

Submitted message text, raw email evidence, and URLs are processed only by the configured services required for the selected investigation. Infrastructure enrichment may use an external geolocation provider for public mail-server IPs. Submit only content you are authorized to process.

  • Submit only the email, URL, or evidence required for the investigation.
  • Remove passwords, access codes, customer identifiers, and financial details before review.
  • Web scan metadata, results, model runs, and limited text previews can be stored in the active Supabase workspace.
  • Follow your organization's retention, consent, and incident-response policies.

Security

VeriTrust should be used as part of a broader security process that includes access control, user education, escalation paths, and audit-friendly workflows.

  • Use strong account credentials and avoid shared logins.
  • Escalate high-risk results to your security or trust-and-safety owner.
  • Do not rely on a single score for account bans, employee discipline, or legal decisions.
  • Review suspicious content in a safe environment and avoid opening unknown links directly.

Account Flow

Documentation, developer guidance, model notes, and legal pages are public. Supabase Auth protects scan execution, the Web CLI, the Evidence Correlation Gateway interface, and every workspace page. A default workspace is created or repaired for an authenticated user when the production schema and service role are configured.

  • Use the Auth page for email/password sign-in, account creation, email confirmation, and password recovery.
  • Use the Dashboard pages for workspace usage, saved scans, API keys, usage limits, and profile settings.
  • Completed web checks are recorded against the active workspace when persistence succeeds.
  • Evidence Correlation Gateway scans submitted through the GUI, Web CLI, Windows PowerShell, or an API integration are stored in the gateway audit tables and included in Dashboard scan history for the API key's organization.
  • Direct model-specific API v1 calls record usage but do not create legacy dashboard scan-history records.

Understanding Results

VeriTrust separates specialist model output, deterministic rule evidence, correlated risk, and forensic evidence coverage. These concepts must not be interpreted as the same number.

  • Verdict: The most likely classification for the submitted content.
  • Confidence: How strongly the model score supports the verdict. Strong confidence is not proof.
  • Confidence band: Weak, Moderate, or Strong, based on the reported confidence score.
  • Risk: Low, Medium, High, or Critical, used for triage and escalation priority.
  • Indicators: Rule-based or model-reported signals that explain why content may need attention.

Phishing checks combine model score with deterministic indicators such as urgency, credential requests, OTP or password language, payment wording, account blocking pressure, short links, suspicious domains, attachments, sender identity, and contact methods.

Link Intelligence checks combine URL classifier output with deterministic URL indicators. It does not claim domain age, live reputation, blocklist status, or confirmed maliciousness.

Fallback behavior differs by check. Email and link result metadata identifies fallback use, unavailable models, and degraded evidence so provider failures are not silently converted into safe outcomes.

False positives and false negatives are possible. When a result is unclear, collect more context, compare against trusted sources, and route the case to a human reviewer.

View model performance notes for the current no-benchmark status and the evidence required before a performance claim.

Reports and Exports

Successful web checks expose report JSON containing the available scan ID, scan type, date, model metadata, summary, scores, evidence or indicators, extracted entities or URL details when applicable, and a disclaimer.

  • Download JSON reports for audit trails or internal case notes.
  • Use Print / Save as PDF for lightweight PDF exports from the browser.
  • Copy the result summary when you need a short escalation note.
  • Saved dashboard scans can be viewed, downloaded, and printed from scan history.

Reports are AI-assisted assessments. They should support review workflows, not replace manual verification for high-impact decisions.