VeriRE

evidence-first verification

AI reads the binary.
The bytes get the final word.

AI agents hallucinate functions, structs and vulnerabilities. VeriRE checks every claim against real disassembly and emulated execution — only what survives is marked Grounded.

Stack buffer overflow in parse_header() Grounded

emulator: saved RIP ← 0x4141414141414141

Use-after-free in lp_close() Refuted

counterexample: pointer nulled after free

struct lp_ctx is 0x40 bytes Inconclusive

offsets 0x30–0x38 unreachable

The problem: confident, unverifiable output

Hallucinated findings

LLMs invent functions, imports and call paths that don't exist in the binary.

Bug bounty slop

Triage teams drown in AI-generated reports with no reproducible evidence.

No ground truth

Model confidence isn't evidence. Nobody can tell what was actually checked.

The pipeline

01

Triage

02

Disassembly

03

Claim Generation

04

Deterministic Verification

05

Evidence Collection

Disassembly match

Instruction-level comparison at the claimed address.

Emulated execution

Run the path with crafted inputs; capture registers.

Signed evidence

SHA-256 of binary and every evidence artifact.

Agent-native

MCP endpoint for Claude Code, Codex, Cursor.

Plug in your agent in one line

Agents submit claims; they only get back what the binary confirms.

Set up integration
$ claude mcp add verire https://verire.lovable.app/mcp \
    --transport http   # OAuth sign-in on first use

> get_claim_verdict(binary="libparse.so")
  ✓ 3 grounded   ✗ 2 refuted   ? 1 inconclusive