VeriCommand
✓
Signed Windows preview

VeriCommand is ready.

Free for Windows 10 and 11 · 143 MB · signed by Northgate Strategic LLC

Version 2.4.0-alpha.19 · preview software · check for updates in the app · watch the 2-minute tour

What’s new in 2.4.0-alpha.19
  • Every guard rule is yours to control in the app: Refuse, Ask me or Off. The app is the only thing that writes the guard’s settings file, and the guard protects that file: a command that clearly writes it is refused, a plain read goes through, and a command it can’t read for sure asks you.
  • The guard hook now runs as its own program beside the connector, so it no longer unpacks itself on every tool call. Installing or repairing the guard changes only this copy’s hook commands; if another VeriCommand copy’s guard is running, that guard stays in charge.
  • Renaming or copying a file, for example git mv secret.env other.env, is now seen by the scope check and the policy check. A workspace too large to read is reported as “policy could not be checked”, never as a pass.
  • A check can no longer run tools an agent planted after its task started. The run copy’s tool inputs are recorded when the task is sent and compared before each check; any difference stops the check with a plain reason.
  • Deleting the newest task file no longer lets its task id be used again.

What the guard covers, and its limits

Version2.4.0-alpha.19
PlatformWindows 10/11 · x64
Signed byNorthgate Strategic LLC
Installer size142,606,872 bytes
SHA-25622BCFCEE480ADEFD3BC150000B3A74CDB40941C862B85331ED79E627B1776CA9
Windows verification: open the downloaded file's Properties → Digital Signatures and confirm the signer is Northgate Strategic LLC (the exact name on the certificate). Do not install a copy with a different signer or hash.
Updating from an earlier preview? Open Settings → VeriCommand updates → Check for updates, then install when the download finishes. Your board and settings stay where they are.
If Windows shows "Windows protected your PC": for a newly released file that is usually SmartScreen still building reputation, not a signature problem. Check the signature and the published hash above before you continue. Click More info — Windows will show the publisher, Northgate Strategic LLC — then Run anyway. If the publisher line shows anything else, stop and don't install.

What we tested before release

  1. Authentic signed package — this file
    Microsoft-trusted Authenticode signature by Northgate Strategic LLC, timestamped, with independent SignTool verification passed on the exact file above.
  2. Every screen walked — this build
    On 2026-10-04, the signed app built from this release's commit was opened on a separate test profile and walked through its nine desktop screens, first run included, with no reported UI errors, then closed normally. Team workspaces are hidden in this build.
  3. Test suites — this build
    On 2026-10-04 the release commit passed the project's automated test runs on Linux: both type checks, 7,778 app tests and 9,891 guard and connector tests. The full suites last ran on Windows on the changes this release merges, before they were merged; on Windows this exact build passed the walk above and the sandbox test below.
  4. Fresh Windows Sandbox — this build
    On 2026-10-04 this exact installer passed a fresh-guest test with no Python and no Git Bash installed: valid signatures, bundled connector 0.5.19, preserved existing client configuration, and the MCP server answered tools/list. The bundled guard denied a secret-file read, let an ordinary command substitution through, in our test still held a destructive git command hidden inside one, matched a custom rule, denied a file edit into the board’s record, and let an ordinary file edit through. The guard hook the bundled connector wrote started under Windows PowerShell and denied a secret-file read; the 2.4.0-alpha.17 form of the same command does not start there.
  5. A real task, end to end — last run on 2.4.0-alpha.16
    On 2026-09-23, on a fresh Windows Sandbox with 4 GB of memory, the 2.4.0-alpha.16 installer was installed, Claude Code was signed in, and a task was created and started from VeriCommand. The agent did the work in its isolated copy, exited cleanly, and its report was recorded; the guard held its git commit for the operator to approve. An earlier attempt on the same machine was refused by the memory check with its reason shown, and ran once more memory was free.

Preview boundary

The guard covers Claude Code sessions. It reads commands, not intent. Known gaps: aliases, script files, shell functions, indirect and symlinked paths, secrets already in the environment, and some compound PowerShell and quoting edge cases. When it can’t read a command (a command held in a variable, an encoded body it can’t decode, a line over 32 KB) or can’t finish checking it within 8 seconds, it asks you instead of letting it through. If the guard hook can’t start or doesn’t answer in time, Claude Code handles the command under its normal permission rules. A seatbelt, not a sandbox.

A recorded decision proves what VeriCommand recorded, not what a client or agent did afterwards, and the record proves integrity, not that the work is right. Slack posting, signed acceptance and multi-step plans are built but switched off in this preview. A check runs the project’s own tools, including files git ignores, such as node_modules/.bin and .npmrc, which an agent could change during its run. The bundled connector is 0.5.19; the separately published Python package remains 0.5.12.