Checked before you trust it
Vev verifies a link against many independent sources and the on-device model, and combines them into one honest danger percentage — with your IP and, where possible, the URL never leaving in the clear.
Private by default, powerful on demand
The everyday layer never touches the network. The deep scan is there when you want a second opinion on a suspicious link.
Always-on, on-device
Deep scan, on request
You decide
Many eyes, one score
Independent feeds catch different things — one is strong on fresh phishing, another on malware, another on engine consensus. Together they cover far more than any single list.
| Local model | on-device trained ML over URL + page content — always on, fully private |
| Google Safe Browsing | malware + social-engineering URLs — checked over Tor |
| VirusTotal | consensus across 70+ engines — best for grey-area links |
| abuse.ch URLhaus | millions of malware-distribution URLs, refreshed constantly |
| abuse.ch ThreatFox | malware IOCs and command-and-control infrastructure |
| AlienVault OTX | community threat-intel pulses across the security world |
Each source runs concurrently with a short timeout, so a slow one never holds up the scan. A source that returns nothing simply doesn't vote — the score comes only from sources that had something to say.
Nothing leaves in the clear
A scanner is only worth using if using it doesn't expose you. Vev's deep scan is built around that:
- Tor-routed. Every scan request goes through Vev's embedded Tor, so the reputation services — and the site itself — see a Tor exit IP, never your real address.
- Local-first. The always-on layer — the model and downloadable blocklists — is checked entirely on your device and transmits nothing. Only the opt-in deep scan sends the URL out, and only over Tor.
- Opt-in. The online scan never runs by itself. The always-on protection is local; you choose when to reach for the network.
Questions about scanning
Is my browsing sent to these scanners?
No, not for everyday browsing. The automatic layer is fully on-device — the local model plus locally-downloaded blocklists — so nothing is transmitted. The multi-source deep scan, which does query online services, is opt-in and runs only when you ask for it on a specific link.
When the deep scan runs, does it leak my IP?
The scan is routed through Vev's embedded Tor, so the services see a Tor exit IP, never yours. Through Tor your IP is never exposed to the scanners. The URL itself is sent to the reputation services so they can check it — over Tor, so it can't be tied back to you. The always-on local layer, by contrast, never transmits anything.
Why not scan every link automatically online?
Because querying an online reputation service means sending it the URL you're about to visit — a privacy cost. Vev keeps the always-on layer local and reserves the online multi-source scan for grey-area links you choose to check.
What decides the final percentage?
Each source votes with an authority weight. A definite hit from a high-authority feed (Google Safe Browsing, VirusTotal consensus) dominates; several weaker sources agreeing also raises it; sources that return nothing simply don't vote. The result is one combined danger percentage plus each source's verdict.
