Vericto

A SQL firewall that understands every query before it reaches your database.

Vericto parses the syntax tree (AST) of every statement and blocks destructive operations: a DELETE without WHERE, a DROP in production, SQL an unsupervised AI agent generates. It works at runtime and before execution, with the same rules.

Download PDF

The problem

A SQL mistake in production gives no warning: a migration that deletes more than intended, a support query without a WHERE, an AI agent with write access. Database permissions say who may write, not whether what is about to run makes sense.

How it works

  • Deterministic AST analysis: the same query always gives the same result. 28 standard rules, plus your own rules in YAML.
  • Clear decisions: each query comes out ALLOWED, FLAGGED or BLOCKED, with the rule, the AST node and a safe alternative.
  • Observe mode: logs everything without blocking for the first days, so you can review activity before turning on enforcement.
  • Postgres, MySQL, Oracle and SQL Server.

Five ways to connect it

ModeWhenWhat it does
Proxy TCP Runtime You point your connection string at the proxy, which runs in your network. Blocks inline, no code changes. Postgres and MySQL.
Runtime API Runtime Your application sends each query before running it and runs it only if the answer is ALLOWED. All four dialects.
CLI Before execution Validates migrations in pre-commit and CI/CD, with an exit code based on the verdict.
Validation API Before execution Send files or batches of SQL over HTTP and get a verdict for each statement.
MCP Before execution AI agents such as Claude Code or Kiro validate SQL while they write it.

Security and data

  • The proxy runs in your infrastructure and you operate it, with your controls and your secrets management. Vericto hosts the control plane: dashboard, rules and audit trail.
  • No dependency on the control plane: if it is unavailable, the proxy keeps evaluating with the last synced ruleset, and with VERICTO_TELEMETRY_BUFFER=disk the audit trail is kept on disk until it is back.
  • Sanitized mode: Vericto never stores the real values of your queries; the dashboard shows the obfuscated statement. In raw mode, text is encrypted at rest with AES-256-GCM.
  • Verifiable evidence: validation reports can be signed with Ed25519 and verified offline, regardless of dashboard retention.
  • Team access: SSO/OIDC and per-workspace roles.

Plans

PlanPriceQueries/monthSQL checks/month (CLI, API, MCP)DatabasesCustom rulesAudit-trail retention
Free$0500K1K1—7 days
Builder$49/mo · $39 annual5M10K3530 days
Team$149/mo · $119 annualUnlimitedUnlimited102090 days
EnterpriseCustomUnlimitedUnlimitedUnlimitedUnlimitedConfigurable

Every connection mode is available on every plan, including Free. Prices in USD, excluding taxes. Full details at vericto.com/pricing.

Let's talk

Write to hello@vericto.com: we reply within 1 business day (Monday to Friday, 9:00–18:00 New York time). Docs at vericto.com/docs and FAQ at vericto.com/faq. Start free at app.vericto.com.