A Letter from a CEO
.png)
Before I started Vetric I thought the harm in cyber came from a particular kind of company, the kind you could point at and stay away from, and I was wrong about that. The same firm can help one customer stop an attack and, somewhere else, help a government find the people protesting against it.
So there were two options, and they are not really a spectrum. Stay blind, which is comfortable and defensible and what most of the industry does, or be the gatekeeper. We chose to be a gatekeeper, which means that if you want to work with the most serious organisations in the world you have to act like you have a large and boring compliance department, whether or not anybody is making you. That decision costs us deals.
What the critics get right
They are right that people can be sorted by things that should never be used to sort them, by political opinion or religion, by who someone prays to or who they love, by whether they are in trouble with money. That is a real capability, and pretending otherwise would insult anyone who has looked at this industry honestly.

Where the criticism goes wrong is on where the harm actually comes from. Most of what goes badly on social platforms needs nothing from companies like mine, because a scam needs an account and a conversation, and a fraudulent campaign needs an advertisement and a link. None of that requires us, and none of it would stop if we disappeared tomorrow.
What sits on the other side is harder to write about, because work that goes well leaves nothing behind and nobody reports the threat that did not arrive, so I will describe it by what our partners spend their days doing instead. They find the people selling children, and they find them while it still matters. They map the networks moving drugs and weapons before those networks reach anyone, and they identify a campaign being built for something that has not happened yet. All of that runs on visibility, and the visibility has to come from somewhere.
What gatekeeping actually means
We ask people to turn their cameras on, which sounds small until you notice that a company unwilling to show you its face in a first conversation is telling you something, and in four years that has never once turned out to be nothing. We look at whether the people behind a company exist in public, with real profiles and real histories and previous employers they are willing to name, because in the parts of this industry doing the work you would not want done the people are in the dark and there is no history to follow. You do not want to work with people who are in the dark.

We turned down a company registered in the United States whose staff, when we looked, were almost entirely somewhere we cannot serve. They told us it was fine.
And we are replacing our vetting with something considerably heavier than a form, because boxes get checked, which means several pages of free text about what you will do with what you find, which capabilities you need and why, whether you are looking at populations or at particular people, who your end users are and which countries they operate in, signed by a named compliance officer putting their own name to the answer.
The test I gave my team was to stop asking what our industry requires and start asking what a compliance department inside a major platform would want to know before approving this applicant, and then to go one step past that. We should be more conservative about this than the platforms are about themselves, and if that is a strange thing for a company in our position to aim at, it is still the only version of this business I want to run.
Where it stops
None of that makes the problem disappear, and I want to be precise about the limit, because there are three kinds of company in this industry and they are not equally guilty.
The first did the work, with real vetting and real refusals, and then sold to a police department in a functioning democracy where an officer used it to look up his ex-wife. That happens, the provider did everything available to them, and the headline still says the technology is the problem.
The second says it does the work. It has a policy and a form and it has arranged not to look too closely, because looking closely is expensive, and this is the most common of the three and the one I watch for inside my own company, because from the inside it never feels like dishonesty. It feels like being reasonable.
The third builds things whose value is mostly in the bad use, and you can identify those by asking what the product would be worth with its worst customer removed, because for some companies the honest answer is most of it.
I would like to tell you we have only ever been the first, but what I can tell you is that the second is a live risk in every company including mine, and that we have not passed this test yet. I said that to my team before I said it here.
Past our direct customer there is another layer, and past that another, and anyone in this industry who tells you the number of times their work ended somewhere they would not approve is zero is either lying to you or has not looked. It is not zero for us.

What would count as proof
A statement is not evidence, so here is what we will publish. Every year, the number of prospects we declined and the number of customers we terminated, with the same methodology each year so that the numbers can be compared, and no revenue figures, because revenue turns this into a story about how much we gave up and that is not the point.
I will be honest about how the conversation started internally. When I brought this work to my team the first version of the discussion was about how to do it without losing deals, which is a reasonable question and the wrong one, because the goal is not to lose less money, and a process designed around not losing money is a form rather than a standard.
We will lose more than we are losing today, and we can already see it, because when you ask people to describe their work in their own words instead of checking a box, some of them cannot and some of them write around it.

What I actually want
The platforms tried to handle this internally first, with filtering and labelling and enormous effort, and it did not scale because the volume is larger than any internal team, so an ecosystem grew into the gap and now does work that cannot be done alone. That is the honest history and everyone involved knows it.
The channels that exist are built for single cases, a specific request and a specific answer, and there is no channel at all for the continuous work of noticing that something is being organised before it happens, which goes on every day without any arrangement covering it.
I would sign one tomorrow, with defined scope and approved use cases, audited and revocable, under conditions tighter than the ones we currently hold ourselves to and with the right to be told no.
I know the public position is that nobody should be doing any of this at all, and I would only point out that the same companies have been customers of this ecosystem when they needed it. I am not saying that to score a point, but because a rule everyone is quietly working around is worse for the platforms than a rule with a door in it. Until there is a door, somebody is standing where one belongs, and I would rather it were somebody who publishes what they refuse.
I did not build this to be a neutral pipe, because a business can have a soul and this is the part of ours I am willing to be judged on. I want to be able to explain what we do to my mother in one sentence, without feeling like I am selling her something.

Omer Bachar, Co-Founder and CEO, Vetric