Runs on the workstation.
Your data stays on your machines.
writ is a single compiled binary that runs where your developers work. Canon runs on your infrastructure. Neither sends your code, decisions or evidence to Verilex.
Single compiled binary
No interpreter, runtime or server to stand up on the workstation.
Local and offline-capable
Code, decisions, records and docs stay on the machine, and travel only to your own paired machines.
Your evidence stays yours
Enforcement evidence goes to your SIEM, not to Verilex.
Air-gapped licensing
Available for networks with no outside connection.
Evidence for your SIEM
A timestamped record of every enforcement event, with retention controls and a Splunk integration.
Unmeasured is never compliant
A machine or rule writ couldn’t verify is reported as unmeasured, not counted as passing.
The assistants writ governs keep their own model access, under your existing agreements with those vendors.
Between the agent and your work.
Your agents act through writ. Allowed actions go through; forbidden ones are refused with your approved alternative. Every decision becomes evidence in your SIEM, and writ reports whether enforcement is actually live.
Assistants and editors
| Assistant | Editors | writ’s panel |
|---|---|---|
| Claude Code | VS Code, JetBrains IDEs | In both |
| Devin | VS Code, JetBrains IDEs | In both |
| GitHub Copilot | VS Code | VS Code |
JetBrains support covers IntelliJ Platform IDEs such as IntelliJ IDEA, PyCharm, GoLand, WebStorm and Rider. More adapters are coming.
A security review pack is available under NDA.
Bring your security team.
We’ll walk through deployment, data handling and evidence on a call.