Skip to content
TopNotchh.
Live CLI / active product

Security evidence for software built with AI in the loop.

Verglos scans repositories for the mistakes AI code specifically makes — wildcard CORS, Math.random for tokens, missing authorization, hallucinated packages — then turns the scan into evidence a team can review, share, or build into a handoff workflow.

Verglos product website and security evidence page screenshot
Real Verglos product surface from the workspace, used as proof of the current product direction.

01 / product proof

The page starts with real product evidence.

This section exists because product pages should not rely on abstract claims. The visual proof must come from the actual product workspace.

Verglos product website and security evidence page screenshot
Real Verglos product surface from the workspace, used as proof of the current product direction.

Product system

Verglos

Verglos scans repositories for the mistakes AI code specifically makes — wildcard CORS, Math.random for tokens, missing authorization, hallucinated packages — then turns the scan into evidence a team can review, share, or build into a handoff workflow.

Live CLI / active product
01

scan

02

finding

03

report

04

evidence

mission

market

architecture

Verglos security evidence product graphic
Product identity asset for the AI-code security evidence layer.

02 / mission

Why this product exists.

Turn AI-code security checks into evidence that can be handed to clients, auditors, or procurement teams.

Customer

Agencies, startups, founders, and developers shipping AI-assisted JavaScript/TypeScript software.

Market

AI-code security, security evidence, agency handoff, procurement readiness, and developer tooling.

Top Notchh relationship

Verglos gives Top Notchh reusable security, evidence, trust, and AI-assisted development discipline.

03 / workflow

The workflow it enters.

The product exists only because this workflow is painful enough to deserve software. If the workflow changes, the product story should change too.

01

scan

02

finding

03

report

04

evidence

04 / problem

The pain it removes.

Agencies and startups shipping AI-generated code get asked to prove it was checked at handover, during procurement, or before diligence. Generic scanners find bugs; Verglos is framed around AI-era failure modes and evidence artifacts.

Verglos knows what AI writes wrong, scores AI-authored files separately from human ones, and turns deterministic findings into evidence artifacts. The engine is Apache-2.0. The business is the evidence.

05 / capabilities

What is supported by the current product story.

01

AI-authored provenance

Every file is scored as human, AI, or mixed so AI-authored risk can be reviewed separately instead of buried in a generic scan.

02

The AI-specific catalogue

Detectors for common AI-era patterns: CORS wildcards, insecure RNG in tokens, auth without authz, mass assignment, hallucinated packages, verbose error handlers, and more.

03

Ten security domains

Full attack surface for modern web + API: injection, auth, authz, cryptography, misconfig, supply chain, API, data exposure, runtime, monitoring — plus the agent surface (MCP, plaintext creds, over-permissioned tools).

04

Signed attestation

The documented direction is a dated, signed report and public verification URL for client handoff and procurement workflows.

05

Rotate, don't just report

Secret rotation adapters are a documented direction. Public claims should stay scoped until each adapter is verified.

06

MCP guardrails for agents

Coding agents call Verglos through MCP tools before writing risky code or installing suspect packages — a checkpoint the agent can't skip.

06 / architecture

Built from real product systems, not a marketing shell.

  • 01

    pnpm/Turborepo TypeScript monorepo.

  • 02

    CLI, scanner, reporter, MCP, shared scoring, and entitlement packages.

  • 03

    Next.js hosted surface with auth, database, checkout, and activation pieces documented.

  • 04

    Deterministic scanner engine; do not position as generic AI magic.

07 / roadmap

What comes next, without pretending it is already done.

  • 01

    Signed attestations and public verify URLs.

  • 02

    White-label client reports and agency dashboard.

  • 03

    SBOM, rotation adapters, and compliance-readiness mapping.

  • 04

    Platform and MCP integrations for AI coding workflows.

08 / constraints

Claims we should not make.

  • 01

    Do not call Verglos a WAF, vault, Vanta replacement, or security engineer replacement.

  • 02

    Do not claim paid traction or conversion without evidence.

  • 03

    Do not present roadmap commands as fully shipped unless verified.

Back to the company

Verglos is one product inside a larger operating system.

Verglos gives Top Notchh reusable security, evidence, trust, and AI-assisted development discipline.