Vericto
A SQL firewall that understands every query before it reaches your database.
Vericto parses the syntax tree (AST) of every statement and blocks destructive operations: a DELETE without WHERE, a DROP in production, SQL an unsupervised AI agent generates. It works at runtime and before execution, with the same rules.
The problem
A SQL mistake in production gives no warning: a migration that deletes more than intended, a support query without a WHERE, an AI agent with write access. Database permissions say who may write, not whether what is about to run makes sense.
How it works
- Deterministic AST analysis: the same query always gives the same result. 28 standard rules, plus your own rules in YAML.
- Clear decisions: each query comes out ALLOWED, FLAGGED or BLOCKED, with the rule, the AST node and a safe alternative.
- Observe mode: logs everything without blocking for the first days, so you can review activity before turning on enforcement.
- Postgres, MySQL, Oracle and SQL Server.
Five ways to connect it
| Mode | When | What it does |
|---|---|---|
| Proxy TCP | Runtime | You point your connection string at the proxy, which runs in your network. Blocks inline, no code changes. Postgres and MySQL. |
| Runtime API | Runtime | Your application sends each query before running it and runs it only if the answer is ALLOWED. All four dialects. |
| CLI | Before execution | Validates migrations in pre-commit and CI/CD, with an exit code based on the verdict. |
| Validation API | Before execution | Send files or batches of SQL over HTTP and get a verdict for each statement. |
| MCP | Before execution | AI agents such as Claude Code or Kiro validate SQL while they write it. |
Security and data
- The proxy runs in your infrastructure and you operate it, with your controls and your secrets management. Vericto hosts the control plane: dashboard, rules and audit trail.
- No dependency on the control plane: if it is unavailable, the proxy keeps evaluating with the last synced ruleset, and with
VERICTO_TELEMETRY_BUFFER=diskthe audit trail is kept on disk until it is back. - Sanitized mode: Vericto never stores the real values of your queries; the dashboard shows the obfuscated statement. In raw mode, text is encrypted at rest with AES-256-GCM.
- Verifiable evidence: validation reports can be signed with Ed25519 and verified offline, regardless of dashboard retention.
- Team access: SSO/OIDC and per-workspace roles.
Plans
| Plan | Price | Queries/month | SQL checks/month (CLI, API, MCP) | Databases | Custom rules | Audit-trail retention |
|---|---|---|---|---|---|---|
| Free | $0 | 500K | 1K | 1 | — | 7 days |
| Builder | $49/mo · $39 annual | 5M | 10K | 3 | 5 | 30 days |
| Team | $149/mo · $119 annual | Unlimited | Unlimited | 10 | 20 | 90 days |
| Enterprise | Custom | Unlimited | Unlimited | Unlimited | Unlimited | Configurable |
Every connection mode is available on every plan, including Free. Prices in USD, excluding taxes. Full details at vericto.com/pricing.
Let's talk
Write to hello@vericto.com: we reply within 1 business day (Monday to Friday, 9:00–18:00 New York time). Docs at vericto.com/docs and FAQ at vericto.com/faq. Start free at app.vericto.com.