Security & deployment

Runs on the workstation.
Your data stays on your machines.

writ is a single compiled binary that runs where your developers work. Canon runs on your infrastructure. Neither sends your code, decisions or evidence to Verilex.

Single compiled binary

No interpreter, runtime or server to stand up on the workstation.

Local and offline-capable

Code, decisions, records and docs stay on the machine, and travel only to your own paired machines.

Your evidence stays yours

Enforcement evidence goes to your SIEM, not to Verilex.

Air-gapped licensing

Available for networks with no outside connection.

Evidence for your SIEM

A timestamped record of every enforcement event, with retention controls and a Splunk integration.

Unmeasured is never compliant

A machine or rule writ couldn’t verify is reported as unmeasured, not counted as passing.

The assistants writ governs keep their own model access, under your existing agreements with those vendors.

How it fits

Between the agent and your work.

Your agents act through writ. Allowed actions go through; forbidden ones are refused with your approved alternative. Every decision becomes evidence in your SIEM, and writ reports whether enforcement is actually live.

AI agentsany supported assistant writ.your decisions · your laws Your codeand approved tools Evidenceto your SIEM ALLOWED · REFUSED WITH REMEDY · RECORDED
Supported today

Assistants and editors

AssistantEditorswrit’s panel
Claude CodeVS Code, JetBrains IDEsIn both
DevinVS Code, JetBrains IDEsIn both
GitHub CopilotVS CodeVS Code

JetBrains support covers IntelliJ Platform IDEs such as IntelliJ IDEA, PyCharm, GoLand, WebStorm and Rider. More adapters are coming.

A security review pack is available under NDA.

Bring your security team.

We’ll walk through deployment, data handling and evidence on a call.

Book a demoAssessment & pilot