Skip to content
Vera5
How-To Extension GitHub
← Back to Vera5

Legal

Vera5 Privacy Policy

Effective Date: June 29, 2026 Last Updated: June 29, 2026

Vera5 is an open-source browser extension and cybersecurity analysis tool designed to detect, analyze, and enrich security-related indicators within webpages and browser-based analyst workflows.

This Privacy Policy explains how information is handled when you:

  • visit the Vera5 website at https://vera5.io;
  • install or use the official Vera5 browser extension;
  • use Vera5 documentation or official project resources;
  • communicate with the Vera5 project; or
  • connect Vera5 to third-party threat-intelligence services, local artificial intelligence models, or user-controlled services.

In this Privacy Policy, “Vera5,” “we,” “us,” and “our” refer to Vera5, operated by Detektr LLC.

1. Summary of Vera5’s Privacy Approach

Vera5 is designed around the following principles:

  • local-first operation;
  • no Vera5 account required for core functionality;
  • no default Vera5 telemetry or behavioral analytics;
  • no Vera5-operated enrichment cloud required for core functionality;
  • bring-your-own API keys;
  • local storage of settings, credentials, preferences, and cached results;
  • no sale of personal information;
  • no advertising profiles;
  • no sale or monetization of browsing activity;
  • no silent upload of complete webpages;
  • no transmission of API keys to Vera5-operated servers; and
  • user control over which third-party intelligence sources receive requests.

When you choose to enrich an indicator, the selected indicator may be transmitted directly from your browser to a third-party provider or user-configured endpoint. Those providers process the indicator according to their own terms, account agreements, and privacy policies.

2. Scope of This Privacy Policy

This Privacy Policy applies to:

  1. the official Vera5 website;
  2. the official Vera5 browser extension;
  3. official Vera5 documentation and project resources operated by us;
  4. communications submitted directly to Vera5; and
  5. any future Vera5-operated service that expressly links to this Privacy Policy.

This Privacy Policy does not govern:

  • independent forks or modified versions of Vera5;
  • unofficial builds or redistributed copies;
  • third-party extensions based on Vera5 source code;
  • third-party threat-intelligence providers;
  • GitHub, the Chrome Web Store, social-media platforms, or other external websites;
  • local artificial intelligence models or localhost services configured by the user;
  • self-hosted services controlled by the user or the user’s organization; or
  • an organization’s internal Vera5 deployment where that organization controls the deployment and associated data processing.

3. Information Handled by the Vera5 Website

3.1 Information We Do Not Intentionally Collect

The current Vera5 website is a static informational website.

Unless this Privacy Policy is updated to state otherwise, the Vera5 website does not intentionally:

  • create user accounts;
  • require authentication;
  • accept payments;
  • collect payment-card information;
  • operate contact or submission forms;
  • use advertising trackers;
  • perform behavioral advertising;
  • create marketing profiles;
  • sell personal information;
  • collect browser history;
  • collect the contents of webpages you visit;
  • collect Vera5 API keys;
  • collect extension settings;
  • collect investigation records; or
  • use Vera5-operated behavioral analytics or telemetry.

3.2 Website Hosting and Technical Records

Our website hosting and infrastructure providers may process limited technical information necessary to deliver and secure the website.

Depending on the provider and configuration, this information may include:

  • IP address;
  • request date and time;
  • requested page or file;
  • browser type;
  • operating system;
  • referring page;
  • approximate geographic region;
  • response status;
  • network information; and
  • security, fraud, or abuse-detection signals.

These records may be generated automatically as part of normal website delivery, network protection, troubleshooting, and security operations.

Vera5 does not use these records to build advertising profiles or track visitors across unrelated websites.

Hosting and infrastructure providers may retain technical records according to their own operational, contractual, legal, and security requirements.

4. Cookies and Similar Technologies

The current Vera5 website does not intentionally set cookies or use:

  • advertising cookies;
  • behavioral tracking cookies;
  • tracking pixels;
  • browser fingerprinting;
  • session-replay tools;
  • cross-site advertising identifiers; or
  • similar tracking technologies.

Because the website does not intentionally use nonessential cookies, Vera5 does not currently display a cookie-consent banner.

External websites reached through links on the Vera5 website may use their own cookies and tracking technologies. Those practices are governed by the external services’ own privacy policies.

If Vera5 later introduces cookies, analytics, authentication, payment processing, embedded third-party media, or similar technologies, this Privacy Policy will be updated and any legally required notice or consent controls will be implemented.

5. Information Handled by the Vera5 Extension

5.1 Local Page Analysis

When activated, or when configured to scan automatically, Vera5 may inspect permitted webpage content within your browser to identify supported cybersecurity artifacts.

These artifacts may include:

  • IP addresses;
  • domains;
  • URLs;
  • file hashes;
  • vulnerability identifiers;
  • email addresses;
  • autonomous system numbers;
  • cryptographic or certificate-related information; and
  • other supported cybersecurity indicators.

This detection process is performed locally within the browser.

Vera5 does not intentionally transmit complete webpage contents, complete browser-tab contents, browser history, cookies, session tokens, email bodies, ticket contents, or dashboard contents to Vera5-operated infrastructure.

Local detection does not necessarily result in an external network request. External enrichment occurs according to the user’s actions, configuration, and enabled providers.

5.2 Information Stored Locally

Vera5 may store information in extension-specific browser storage on your device, including:

  • extension settings;
  • enabled or disabled features;
  • enabled intelligence providers;
  • API keys supplied by you;
  • provider configuration;
  • domain-specific permissions or restrictions;
  • cached enrichment results;
  • cache timestamps;
  • detected or selected indicators;
  • investigation sessions;
  • collections;
  • analyst notes;
  • labels and tags;
  • watchlists;
  • export preferences;
  • workflow history;
  • local AI endpoint settings; and
  • other locally configured operational information.

This information ordinarily remains on your device unless you:

  • export it;
  • copy it to the clipboard;
  • save it to a file;
  • transmit an indicator to an enabled provider;
  • configure Vera5 to communicate with a local or self-hosted service;
  • use browser-sync functionality outside Vera5’s direct control; or
  • use a future optional Vera5 service that clearly discloses different data handling.

Removing Vera5 may not remove:

  • files previously exported from Vera5;
  • information copied to the clipboard;
  • browser backups;
  • synchronized browser data;
  • information retained by third-party providers; or
  • information stored outside Vera5’s extension storage.

5.3 API Keys and Credentials

Vera5 uses a bring-your-own-key model for supported third-party services.

API keys supplied by users are intended to be stored locally in extension-specific browser storage or in a user-controlled local or self-hosted service.

Vera5 does not intentionally:

  • transmit API keys to Vera5-operated servers;
  • pool API credentials among users;
  • sell or rent API credentials;
  • use one user’s credentials for another user;
  • publish user credentials;
  • include credentials in exports by default; or
  • knowingly include credentials in public logs, reports, or issue submissions.

When required for authentication, an API key is necessarily transmitted to the corresponding third-party provider when Vera5 performs a request to that provider.

Browser-local storage is not equivalent to dedicated hardware-backed credential storage. Users are responsible for protecting:

  • their device;
  • their operating-system account;
  • their browser profile;
  • their backups;
  • their provider accounts; and
  • their API credentials.

Users should revoke and replace an API key if they believe it has been exposed or compromised.

6. Third-Party Enrichment Requests

Vera5 may connect directly to third-party threat-intelligence, infrastructure, reputation, vulnerability, or security services selected by the user.

Supported or planned providers may include services such as:

  • AlienVault OTX;
  • AbuseIPDB;
  • VirusTotal;
  • URLScan.io;
  • GreyNoise;
  • Shodan;
  • Censys;
  • ThreatFox;
  • MalwareBazaar;
  • URLhaus;
  • RDAP or WHOIS services;
  • MISP;
  • OpenCTI;
  • TheHive; and
  • other user-configured providers or endpoints.

The availability of a provider may vary by Vera5 version.

When you request enrichment, Vera5 may send the selected indicator and necessary request information directly to the enabled provider.

The provider may receive:

  • the indicator value;
  • your IP address;
  • request date and time;
  • your API credential;
  • browser or network metadata;
  • service-specific request parameters; and
  • other information normally transmitted as part of an HTTPS request.

The provider may log, retain, analyze, correlate, or disclose that information according to its own:

  • privacy policy;
  • service terms;
  • API agreement;
  • account configuration;
  • retention policies; and
  • legal obligations.

Vera5 does not control third-party providers’ data practices.

You should not send a confidential, internal, classified, regulated, privileged, proprietary, or otherwise sensitive indicator to a third-party provider unless:

  • you are authorized to do so;
  • the transmission is permitted by your organization;
  • you understand the provider’s handling practices; and
  • the transmission is legally and operationally appropriate.

7. User Controls

Depending on the installed version, Vera5 may provide controls that allow users to:

  • disable automatic enrichment;
  • require manual enrichment;
  • enable or disable individual providers;
  • restrict Vera5 on particular websites;
  • prevent queries involving internal or private indicators;
  • use cached results;
  • use a quiet or reduced-network mode;
  • preview outbound operations;
  • clear locally stored information;
  • remove API credentials; or
  • use a local or self-hosted endpoint.

These controls are intended to reduce unintended disclosure. They do not replace the user’s responsibility to determine whether an indicator may appropriately be submitted to a third party.

8. Local Artificial Intelligence and Self-Hosted Services

Vera5 may support optional connections to:

  • local AI models;
  • llama.cpp servers;
  • localhost APIs;
  • local language-model runtimes;
  • private organizational services; or
  • user-controlled self-hosted backends.

When you configure such a service:

  • Vera5 may send the information necessary to perform the requested operation to the endpoint you configured;
  • the endpoint may process or retain information according to its own configuration;
  • the endpoint is not operated by Vera5 unless it is expressly identified as a Vera5-operated service; and
  • you are responsible for securing, configuring, monitoring, and maintaining the endpoint.

Information submitted to a local model may include:

  • a selected indicator;
  • normalized enrichment results;
  • source findings;
  • analyst-provided notes;
  • requested report content; or
  • other information required for the selected feature.

Vera5 is not intended to send the following information to a local AI endpoint unless a user knowingly and explicitly configures functionality requiring it:

  • API keys;
  • browser cookies;
  • account passwords;
  • session tokens;
  • unrelated browsing history; or
  • unrelated complete webpage contents.

Users should review the configuration and logging behavior of their local or self-hosted services before using them with sensitive information.

9. Browser Permissions

Vera5 may request browser permissions necessary to provide its disclosed functionality.

These may include permission to:

  • use extension-specific storage;
  • interact with the active tab;
  • execute or inject extension components;
  • identify supported artifacts in permitted webpage content;
  • communicate with approved external providers;
  • display extension interfaces; and
  • perform user-requested extension operations.

Vera5 uses browser permissions for its disclosed cybersecurity-analysis functionality.

Current permissions and their technical implementation may be reviewed through the official Vera5 source repository and extension manifest.

10. Chrome Web Store Limited Use Disclosure

Vera5’s use and transfer of information received through browser permissions will comply with the Chrome Web Store User Data Policy, including applicable Limited Use requirements.

Information accessed through browser permissions is used only to provide or improve prominent user-facing Vera5 functionality.

Vera5 does not use browser-accessed information for:

  • targeted advertising;
  • personalized advertising;
  • unrelated marketing;
  • creditworthiness determinations;
  • lending decisions;
  • selling information to data brokers;
  • creating unrelated consumer profiles;
  • surveillance unrelated to Vera5’s disclosed purpose; or
  • purposes materially unrelated to cybersecurity analysis and user-requested Vera5 functionality.

Vera5 does not sell browser-accessed information.

Human access to information processed through Vera5 is not intended or permitted except when:

  1. the user expressly requests support and voluntarily provides the information;
  2. access is necessary to investigate security, fraud, abuse, or legal compliance;
  3. access is necessary to provide an optional service knowingly requested by the user; or
  4. information has been aggregated or anonymized so it cannot reasonably identify an individual.

11. Information You Voluntarily Provide

You may voluntarily provide information when you:

  • contact Vera5 by email;
  • submit a GitHub issue;
  • submit a pull request;
  • participate in a project discussion;
  • submit a vulnerability report;
  • request technical support;
  • provide feedback; or
  • communicate through an official Vera5 community channel.

This information may include:

  • your name;
  • username;
  • email address;
  • organization;
  • message contents;
  • technical logs;
  • screenshots;
  • browser and device information;
  • extension configuration;
  • sample indicators; and
  • other information you choose to provide.

Do not include the following in public issues, discussions, screenshots, or support requests:

  • API keys;
  • passwords;
  • access tokens;
  • session cookies;
  • classified information;
  • protected customer information;
  • proprietary investigation data;
  • regulated information; or
  • unnecessary personal information.

Vera5 may use voluntarily submitted information to:

  • respond to communications;
  • investigate defects;
  • provide support;
  • address vulnerabilities;
  • evaluate requested features;
  • improve Vera5;
  • maintain project records;
  • protect Vera5 and its users;
  • enforce project rules; and
  • comply with legal obligations.

Public submissions to GitHub and other public platforms may remain publicly available and may be copied, indexed, archived, or redistributed by third parties.

12. No Sale or Advertising Use

Vera5 does not:

  • sell personal information;
  • rent personal information;
  • share personal information for cross-context behavioral advertising;
  • operate an advertising network;
  • use detected indicators for advertising;
  • use browsing activity to build advertising profiles;
  • use investigation records to build marketing profiles; or
  • monetize users’ API keys or enrichment results.

13. How Information May Be Disclosed

Information under Vera5’s control may be disclosed in the following circumstances.

13.1 At Your Direction

Information may be disclosed when you request, direct, or authorize the disclosure.

13.2 Operational Service Providers

Limited information may be processed by providers supporting:

  • website hosting;
  • infrastructure delivery;
  • email;
  • source-code hosting;
  • security;
  • abuse prevention; or
  • other project operations.

These providers process information under their own contractual, technical, and legal obligations.

13.3 Legal and Safety Requirements

Information may be disclosed when Vera5 reasonably believes disclosure is necessary to:

  • comply with applicable law;
  • respond to valid legal process;
  • respond to a lawful governmental request;
  • protect the rights, property, security, or safety of Vera5, users, or the public;
  • investigate fraud, abuse, or security incidents;
  • establish, exercise, or defend legal claims; or
  • enforce applicable agreements or project rules.

13.4 Business Transactions

If Vera5, Detektr LLC, or relevant project assets are involved in a:

  • merger;
  • acquisition;
  • financing;
  • corporate reorganization;
  • bankruptcy;
  • sale of assets; or
  • similar business transaction,

information under Vera5’s control may be reviewed or transferred as part of that transaction.

Any successor will remain subject to applicable law and any privacy commitments that continue to apply.

Because most Vera5 extension information is stored locally and is not possessed by Vera5, locally stored extension information would not ordinarily be available for transfer by Vera5 or Detektr LLC.

14. Data Retention

Vera5 retains information under its control only for as long as reasonably necessary for the purposes described in this Privacy Policy, including:

  • support;
  • security;
  • dispute resolution;
  • project administration;
  • recordkeeping; and
  • legal compliance.

Retention periods may vary:

  • Website technical records may be retained by infrastructure providers for operational and security purposes.
  • Email and support communications may be retained while relevant to the request and for reasonable administrative records.
  • Security reports may be retained to document vulnerabilities, investigations, and remediation.
  • Public GitHub contributions may remain available indefinitely as part of the project’s public development history.
  • Locally stored extension information remains on the user’s device until deleted, expired, overwritten, cleared, or removed through browser or operating-system controls.
  • Information submitted to a third-party provider is retained according to that provider’s policies.

15. Security

Vera5 uses reasonable technical and organizational safeguards appropriate to the nature of the information under its control.

Safeguards may include:

  • local-first processing;
  • data minimization;
  • credential masking;
  • excluding credentials from exports by default;
  • HTTPS communications with supported providers;
  • restricted browser permissions;
  • source attribution;
  • cache controls;
  • dependency scanning;
  • secret scanning;
  • redaction controls;
  • open-source review; and
  • security-focused development practices.

No software, network transmission, or storage system can be guaranteed completely secure.

Vera5 cannot guarantee absolute security.

Users are responsible for:

  • securing their devices;
  • securing their operating-system accounts;
  • securing their browser profiles;
  • protecting their API keys;
  • configuring third-party services appropriately;
  • reviewing requested permissions;
  • keeping Vera5 and related software updated;
  • evaluating the sensitivity of indicators before enrichment; and
  • reporting suspected vulnerabilities responsibly.

Security concerns and vulnerability reports may be sent to:

Vera5io@proton.me

Use a clear subject line such as:

Security Report – Vera5

Do not publicly disclose an unpatched vulnerability before Vera5 has had a reasonable opportunity to investigate and coordinate remediation.

16. Your Choices and Controls

Depending on the installed version, users may be able to:

  • disable Vera5;
  • uninstall the extension;
  • disable highlighting;
  • disable automatic scanning;
  • use manual-only enrichment;
  • disable individual providers;
  • remove stored API keys;
  • clear cached results;
  • delete local investigation records;
  • delete collections or notes;
  • restrict operation on selected domains;
  • disable local AI functionality;
  • revoke API keys through the applicable provider;
  • clear extension storage through browser settings; and
  • delete exported files from their device.

Because Vera5 does not ordinarily maintain centralized user accounts or a centralized user database, Vera5 may be unable to identify, access, or delete information stored solely on the user’s device.

17. Privacy Rights

Depending on your location and the applicability of relevant privacy laws, you may have rights concerning personal information under Vera5’s control.

These rights may include the right to:

  • request access;
  • request correction;
  • request deletion;
  • receive a copy of information;
  • restrict certain processing;
  • object to certain processing;
  • withdraw consent;
  • opt out of certain sales, sharing, targeted advertising, or profiling;
  • appeal the denial of a request; or
  • submit a complaint to a privacy regulator.

Vera5 does not currently sell personal information, share personal information for cross-context behavioral advertising, or conduct targeted advertising.

Privacy requests may be submitted to:

Vera5io@proton.me

Use the subject line:

Privacy Request – Vera5

A request should provide enough information to identify:

  • the person making the request;
  • the nature of the request;
  • the communication or service involved; and
  • any relevant records.

Vera5 may need to verify your identity or authority before acting on a request.

Vera5 will not discriminate against an individual for exercising an applicable privacy right.

Information stored only in your browser, device, local AI service, self-hosted service, or third-party account must ordinarily be managed through that system because Vera5 does not possess or control it.

18. California Privacy Notice

This section supplements this Privacy Policy for California residents.

To the extent the California Consumer Privacy Act, as amended, applies to Vera5, eligible California residents may have the right to:

  • know the categories of personal information collected;
  • know the sources and purposes of collection;
  • know the categories of recipients;
  • request specific pieces of personal information;
  • request deletion;
  • request correction;
  • obtain information in a portable format;
  • opt out of the sale or sharing of personal information;
  • limit certain uses of sensitive personal information; and
  • receive equal service when exercising privacy rights.

Vera5 does not sell personal information.

Vera5 does not share personal information for cross-context behavioral advertising.

Vera5 does not knowingly use personal information for targeted advertising.

Because Vera5 does not currently engage in those activities, Vera5 does not currently provide a “Do Not Sell or Share My Personal Information” link.

The limited categories of information Vera5 may process are described in this Privacy Policy and may include:

  • basic website request information;
  • security or abuse-prevention records; and
  • information voluntarily provided through email, support requests, or public project channels.

19. Florida Residents

To the extent the Florida Digital Bill of Rights or another applicable Florida privacy law applies to Vera5, eligible Florida residents may exercise available privacy rights by contacting:

Vera5io@proton.me

Vera5 does not sell personal information, conduct targeted advertising, or operate as a large-scale consumer-data business.

20. European Economic Area, United Kingdom, and Switzerland

Where applicable law requires a lawful basis for processing personal information, Vera5 may rely on one or more of the following:

  • Consent: when you voluntarily provide information or request an optional function.
  • Contractual necessity: when processing is required to provide a service you request.
  • Legitimate interests: to operate, secure, maintain, support, and improve Vera5 where those interests are not overridden by your rights.
  • Legal obligation: when processing is required by law.
  • Protection of rights: when processing is necessary to establish, exercise, or defend legal claims.

Where required, appropriate safeguards will be used for international transfers of personal information.

Eligible individuals may have the right to lodge a complaint with their local data-protection authority.

21. Children’s Privacy

Vera5 is a professional cybersecurity tool and is not directed to children under 13 years of age or to children below the minimum age required by applicable local law.

Vera5 does not knowingly collect personal information from children through its website or extension.

If you believe a child has submitted personal information to Vera5, contact:

Vera5io@proton.me

Vera5 will review the report and take appropriate action where required.

22. Sensitive, Confidential, and Regulated Information

Vera5 is not intended to function as a repository for:

  • passwords;
  • authentication tokens;
  • financial-account information;
  • protected health information;
  • classified information;
  • export-controlled information;
  • privileged legal communications;
  • government identification numbers;
  • biometric information;
  • confidential customer records; or
  • other regulated or highly sensitive personal information.

Do not knowingly transmit such information to a third-party provider through Vera5 unless:

  • you are authorized to do so;
  • the transmission is lawful;
  • the transmission complies with your organization’s policies; and
  • you understand the provider’s handling practices.

23. Automated Scores, Summaries, and Analysis

Vera5 may calculate local:

  • risk scores;
  • labels;
  • severity ratings;
  • confidence indicators;
  • enrichment summaries;
  • correlations; or
  • AI-assisted explanations.

These outputs are intended to assist human cybersecurity analysis.

They are not definitive findings and should not be treated as a substitute for:

  • independent verification;
  • professional judgment;
  • organizational procedures; or
  • authoritative provider records.

Vera5 does not use these outputs to make decisions regarding:

  • employment;
  • credit;
  • housing;
  • insurance;
  • education;
  • healthcare;
  • legal rights; or
  • access to essential services.

24. External Links

The Vera5 website and extension may contain links to third-party websites and services, including:

  • GitHub;
  • the Chrome Web Store;
  • threat-intelligence providers;
  • documentation resources;
  • social-media platforms; and
  • external cybersecurity tools.

Vera5 is not responsible for the content, availability, security, or privacy practices of external services.

Opening an external pivot link may disclose information to the destination service, including:

  • your IP address;
  • browser information;
  • request time;
  • referring information; and
  • the indicator included in the destination URL.

Users should review the destination service’s terms and privacy policy before submitting sensitive information.

25. Open-Source Software and Independent Deployments

Vera5 source code may be used, copied, modified, and distributed according to its applicable open-source license.

A person or organization that modifies, redistributes, independently hosts, or internally deploys Vera5 may have privacy practices different from those described in this Privacy Policy.

This Privacy Policy applies only to official Vera5 websites, official Vera5 extension builds, and services operated by Vera5 or Detektr LLC unless expressly stated otherwise.

The applicable open-source license governs permission to use, modify, and distribute the software.

This Privacy Policy governs information practices associated with official Vera5 operations.

26. Changes to This Privacy Policy

Vera5 may update this Privacy Policy to reflect:

  • changes in Vera5 functionality;
  • new integrations or providers;
  • new optional services;
  • security changes;
  • legal or regulatory developments;
  • business changes; or
  • corrections and clarifications.

The updated policy will be published with a revised Last Updated date.

If a change materially alters how Vera5 collects, uses, stores, or discloses personal information, Vera5 will provide notice appropriate to the circumstances.

Notice may be provided through:

  • the Vera5 website;
  • the extension interface;
  • the Chrome Web Store listing;
  • release notes;
  • the official source repository; or
  • another reasonable communication channel.

Continued use of Vera5 after an updated policy becomes effective constitutes acknowledgment of the revised policy to the extent permitted by law.

27. Contact Information

Questions, privacy requests, security reports, or concerns regarding this Privacy Policy may be directed to:

Vera5
Operated by: Detektr LLC
Email: Vera5io@proton.me
Website: https://vera5.io

For privacy matters, use the subject line:

Privacy Request – Vera5

For security matters, use the subject line:

Security Report – Vera5

28. Publication and Accessibility

This Privacy Policy should remain reasonably accessible through:

  • the Vera5 website footer;
  • the Chrome Web Store listing;
  • the official Vera5 source repository;
  • the extension settings or About interface; and
  • any future Vera5-operated service that handles user information.

Vera5

Open-source analyst tooling for IOC enrichment.

Project

  • GitHub

Docs

  • How-To
  • Product Vision
  • Security Model

Site

  • Tool
  • Principles
  • Status

Legal

  • Privacy Policy
  • Terms of Service
  • Security & Privacy
  • Third-Party Services Disclosure
  • Cookie Policy
vera5.io Open source · MIT