Skip to content
Top Notchh.

Journal

Verglos · Product principle

Aug 20, 2026

1 min read

By Top Notchh Team

Reviewed Sep 1, 2026

Sources: company verified

What Verglos 2.0 alpha refuses

Four product boundaries for Verglos: no autonomous attacks, no cloud requirement for scanning, no compliance theater, and no roadmap passed off as shipping.

In brief

  • Verglos is not designed as an autonomous offensive agent or compliance platform.
  • The working scanner remains local-first.
  • Unshipped roadmap concepts are labeled as proposals.
A local scanner inside four clear boundaries marking excluded product directions.

Product strategy includes the authority a tool refuses to take. Four boundaries define the current Verglos direction.

No autonomous attacks

Verglos is not intended to choose external targets, probe live systems, or run an open-ended offensive campaign. The proposed hunt workflow is bounded local verification against code the user is authorized to test. In 2.0.0-alpha.1, even that workflow is not available.

Four excluded lanes surround the current local scanner: autonomous attack, mandatory cloud analysis, compliance certification, and roadmap theater.

No cloud requirement for the scanner

The scanner's useful path should remain local and should not require source upload or an account. This is a trust-model choice, not a claim that all hosted analysis is wrong. Mature cloud platforms solve organization-wide problems that a local alpha does not.

No compliance theater

A scanner report or future signed summary cannot replace a compliance program, penetration test, audit, threat model, or secure development lifecycle. Evidence can support those processes only when its scope and limits are clear.

No roadmap presented as product truth

Command names, mockups, and strategy notes are not shipped capabilities. hunt, attest, hosted verification, agent integrations, and paid plans remain proposals or shells until the public package demonstrates them.

This refusal is especially important for a security product. Users must be able to trace capability claims to code, documentation, or a service they can actually use.

The current product is smaller: a local scanner for JavaScript and TypeScript. Keeping that boundary explicit gives the future product room to earn broader claims rather than borrowing them early.

Evidence ledger

Sources and verification

  1. Verglos CLI repositoryTop Notchh Solutions · canonical · checked Sep 1, 2026
  2. Verglos on npmnpm · canonical · checked Sep 1, 2026