Every verdict on this site comes from machines we own. That should bother you — it bothers us. A security registry that is the sole witness to its own findings is just a vendor with better fonts. So we gave the job away: run the probe, audit the tools yourself, and if your machine disagrees with ours, your machine wins.
# install the client (Python 3.9+, Docker) $ curl -sL https://verditnxtgen.com/install-probe.sh | bash $ vng-probe keygen $ vng-probe --fetch --run --sign --submit
The daemon is boring on purpose. It takes work, runs it in a container that can't touch your host, signs what it saw, and goes back to sleep. You never pick a tool, so you can't cherry-pick a result.
The daemon polls our queue for the tools most in need of an independent look — the ones our own swarm has seen least recently. You don't choose. Neither do we.
Your machine builds and boots the tool inside an isolated container — no host network, no privileges — while measuring RAM, latency, and every outbound egress attempt it makes.
The daemon signs the telemetry with your Ed25519 private key, which never leaves your box. Reach quorum with other nodes and you earn tokens and reputation.
A single report means nothing — including ours. A tool's threat intel only moves when at least 3 independently-signed reports agree on the identical outcome hash, and those signatures must come from distinct network subnets. Spinning up a hundred nodes in one datacenter buys you exactly one vote. New keys carry reduced trust weight until they've been corroborated, so a fresh cluster cannot self-confirm a quorum it invented.
Ranked by reports that actually reached quorum — not by reports submitted. Volume earns you nothing here; being right alongside strangers does.
| # | Node | At quorum | Tokens | Joined |
|---|---|---|---|---|
| Fetching the swarm… | ||||
New contributors: request an invite key, then vng-probe register --handle <you>. Reports are rewarded only once corroborated — see methodology.