Threat scanning

Checked before you trust it

Vev verifies a link against many independent sources and the on-device model, and combines them into one honest danger percentage — with your IP and, where possible, the URL never leaving in the clear.

Two layers

Private by default, powerful on demand

The everyday layer never touches the network. The deep scan is there when you want a second opinion on a suspicious link.

Always-on, on-device

Every navigation is scored by the local trained model and checked against blocklists that Vev downloads and holds on your machine (URLhaus and more). Nothing about the URL is transmitted — this layer works with the network unplugged.

Deep scan, on request

On a grey-area link, choose Deep scan from the nudge or the command palette. Vev queries several independent reputation services at once and blends their verdicts with the local model into a single percentage — routed through Tor so the services see a Tor exit, not you.

You decide

The result appears in the Dynamic Island with each source's verdict. If it's dangerous, go back; if you trust it, open anyway. Vev informs — it doesn't silently decide for you.
The sources

Many eyes, one score

Independent feeds catch different things — one is strong on fresh phishing, another on malware, another on engine consensus. Together they cover far more than any single list.

Local modelon-device trained ML over URL + page content — always on, fully private
Google Safe Browsingmalware + social-engineering URLs — checked over Tor
VirusTotalconsensus across 70+ engines — best for grey-area links
abuse.ch URLhausmillions of malware-distribution URLs, refreshed constantly
abuse.ch ThreatFoxmalware IOCs and command-and-control infrastructure
AlienVault OTXcommunity threat-intel pulses across the security world

Each source runs concurrently with a short timeout, so a slow one never holds up the scan. A source that returns nothing simply doesn't vote — the score comes only from sources that had something to say.

Privacy of the scan itself

Nothing leaves in the clear

A scanner is only worth using if using it doesn't expose you. Vev's deep scan is built around that:

  • Tor-routed. Every scan request goes through Vev's embedded Tor, so the reputation services — and the site itself — see a Tor exit IP, never your real address.
  • Local-first. The always-on layer — the model and downloadable blocklists — is checked entirely on your device and transmits nothing. Only the opt-in deep scan sends the URL out, and only over Tor.
  • Opt-in. The online scan never runs by itself. The always-on protection is local; you choose when to reach for the network.
FAQ

Questions about scanning

Is my browsing sent to these scanners?

No, not for everyday browsing. The automatic layer is fully on-device — the local model plus locally-downloaded blocklists — so nothing is transmitted. The multi-source deep scan, which does query online services, is opt-in and runs only when you ask for it on a specific link.

When the deep scan runs, does it leak my IP?

The scan is routed through Vev's embedded Tor, so the services see a Tor exit IP, never yours. Through Tor your IP is never exposed to the scanners. The URL itself is sent to the reputation services so they can check it — over Tor, so it can't be tied back to you. The always-on local layer, by contrast, never transmits anything.

Why not scan every link automatically online?

Because querying an online reputation service means sending it the URL you're about to visit — a privacy cost. Vev keeps the always-on layer local and reserves the online multi-source scan for grey-area links you choose to check.

What decides the final percentage?

Each source votes with an authority weight. A definite hit from a high-authority feed (Google Safe Browsing, VirusTotal consensus) dominates; several weaker sources agreeing also raises it; sources that return nothing simply don't vote. The result is one combined danger percentage plus each source's verdict.