Verand is a content operations platform, and AI does the drafting work inside it. Specifically, it writes an article from a brief, researches search results and competitor pages to build that brief, proposes an edit when a check fails in the editor, generates the hero image at the top of a draft, labels the clusters on your topical map, and answers questions about your own site through our MCP connector.
Everything else the product does is ordinary software. Crawling your site, joining your Search Console and Analytics figures to your pages, tracking a ranking, running the validators: none of that is a model deciding anything.
What the AI never does is decide what gets published. That’s the line the rest of this page describes, from four directions: your content, your approval, our checks, and what the AI is allowed to touch.
This page is about the product. How the posts on the Verand blog are written and who is answerable for them is a different question, answered on Editorial Standards.
We don’t train models on your content, and neither do the model providers we call. Your articles, your knowledge base and your site data are processed to produce your output, and nothing else.
Those are two different kinds of promise and both are load bearing. The first is ours. The second is contractual: the model providers Verand calls don’t train on API inputs by default, which is a term you can check in their own published API terms rather than take on our word.
We don’t sell your data, hand it to data brokers, use it for advertising, or use it to train generalised AI or machine-learning models. How long we keep it and how you get it deleted are set out in the Privacy Policy and restated on the Security page.
Nothing reaches a live site without an explicit human action in Verand. Every AI output is a draft, a suggestion or a report. You read it, change it, or throw it away.
- An article arrives as a draft in the editor. Publishing it is a separate, deliberate action.
- A proposed fix is shown as a preview against the current text. You accept it or you don’t, and the checks re-run against whatever you end up with.
- A change to a connected site is prepared, shown to you, and applied only when you trigger it. Our scheduled routines analyse and report. None of them publishes.
- The MCP connector can draft, refresh and research. It cannot publish, and there’s no setting that changes that.
A hard-tier compliance block is not overridable by the AI, and not by
us. Hard tier covers the unambiguous, lawsuit-class claims: a guaranteed return, a
missing required disclaimer, a jurisdiction violation. When one fires, the article is
Blocked until the text changes. Review-tier rules, the context-sensitive ones a
deterministic check can’t judge perfectly, can be overridden by a person, and only by a
person, with a written justification recorded against the article.
We build it this way on purpose. Our customers are the ones whose regulator asks awkward questions, and for them the review is the product rather than an obstacle to it.
The validators and the compliance gate are deterministic code. They are not a model being asked for an opinion. The same article produces the same verdict every time, on every run, for every customer.
This is the part of Verand we’d most want a reviewer to test. Ask a language model whether a draft is compliant and you get a fluent answer that may differ on the next run and can’t be reproduced afterwards. Verand’s 46 checks are written as code against an encoded rule set, so a result is reproducible, explainable and the same tomorrow. When a draft is blocked you get the rule id, the phrase that triggered it and the tier, not a paragraph of prose about how it feels.
The boundary is worth stating precisely, because we hold to it:
- Suggested by a model: the research targets. Which terms and which evidence a brief says to cover are distilled from competitor pages by a model, and they’re advisory and editable by you.
- Decided by code: the grading against those targets, every validator, the three quality dials, and the compliance gate readout. None of it is model judged.
- Labelled where it isn’t: parts of the site audit use a model to read a page and comment on it. Those read as advisory findings, and they never gate a publish.
The AI reaches exactly what your account reaches, and no further. It can’t see another customer’s data, because your account can’t.
- Google Search Console and Google
Analytics 4 are connected read-only, under
webmasters.readonlyandanalytics.readonly. Nothing in either account can be modified. - A content management system or code repository is read as far as is needed to analyse the pages you point us at, and written to only as a draft or a pull request for your approval.
- Google Business Profile, where you connect a listing, is read in order to audit it. We write only items you’ve explicitly approved, and never change a listing’s name, address, phone number, categories or hours on our own.
- Your content can’t be deleted by the AI. There is no delete path available to it, in the product or through the connector.
You can disconnect any integration under Settings → Integrations at any time. The Security page sets out the same ground in the form a vendor review usually asks for.
Models get things wrong. They state a figure with more confidence than it deserves, attribute something to a source that doesn’t say it, and describe a rule in language that reads correct and isn’t. That isn’t a defect we expect to engineer away, and we don’t design as though we will.
The checks and the human approval step exist because of it. We don’t claim the output is always correct. What we claim is narrower and testable: every draft is put through the same deterministic checks, the gate is honest about what it did and didn’t verify, and a person reads it before anything goes live. Treat a draft as a draft.
The same honesty applies to the rules themselves. Our compliance packs are AI researched and operator reviewed. They are not attorney reviewed, we don’t describe them as though they are, and Verand doesn’t give legal advice. A pack is validated against a governing body’s published rules; whether it applies to your practice is a question for your own counsel.
Anthropic provides the model that drafts and analyses. OpenAI provides the text embeddings behind your knowledge base and content store. Both appear in the subprocessor list in the Privacy Policy, reproduced on the Security page. That list is the authoritative one and covers the rest of the stack too.
Verand also queries third-party sources for search results, keyword metrics, backlinks, domain authority, page speed and local data. Those sources receive a domain, a keyword or a competitor’s URL. They receive no customer content and no personal data, so they supply reference data rather than process yours, and we name them to no one.
We’ll update the subprocessor list before adding a provider that processes your content.
Security and data questions, including how any of the above is implemented:
security@verand.ai.
Everything else, including anything the product got wrong:
support@verand.ai.
Brussel Investments, Inc., d/b/a Verand
1718 Capitol Ave, Cheyenne, WY 82001, USA
If an AI questionnaire is part of your vendor review, send it to the security address. We answer them, and we answer “no” where the answer is no.