VerisAI crawler identity declaration
Information for website security and firewall administrators.
This document identifies the VerisAI Index Scanner, explains why it requests public website resources, and provides a direct contact.
Identity
Operator
VerisAI
BELVO, s.r.o.
Purpose
Public-site AI visibility index assessment.
Contact
Declaration version: 1.0 · Issued: 2026-07-29
Machine-readable declaration: /.well-known/verisai-crawler.json
How generic technical requests identify themselves
Generic technical requests use this exact HTTP User-Agent:
VerisAI-IndexScanner/1.0 (+https://verisai.eu/crawler; AI visibility index scan; support@verisai.eu)
This identity is used for the public homepage, HTTP-to-HTTPS redirect check, robots.txt, sitemap, llms.txt, llms-full.txt, and the small set of public AI-discovery files.
Scope and safeguards
- Only publicly reachable website resources are assessed.
- The scanner does not authenticate, submit forms, use credentials, or bypass logins and paywalls.
- It collects technical response data and derived AI-readiness signals. Public-response-derived assessment results may be retained for VerisAI index and monitoring operations.
- Source IP addresses may vary during local operation; they are not a stable public allow-list or identity proof.
- This is a transparency declaration on VerisAI's HTTPS domain, not a CA-issued, TLS-client, or cryptographic certificate.
AI bot access measurement
Every request VerisAI makes identifies itself with the single User-Agent shown above. The scanner does not send any other company's crawler User-Agent, and does not claim to be GPTBot, ClaudeBot, Google-Extended, PerplexityBot, OAI-SearchBot or GrokBot.
What a site declares about those named crawlers is read from its own robots.txt, which is a public statement the site publishes. What VerisAI additionally records is whether this scanner, under the identity above, received the page. Those two findings are reported separately and are never merged into a claim about a specific provider's access.
Until 28 August 2026 part of the assessment did send those providers' User-Agent strings. That practice was ended: a User-Agent string does not authenticate a crawler. Providers publish IP ranges, and often reverse DNS, precisely so their crawlers can be identified by something a third party cannot copy, so a request carrying a provider's name from VerisAI's own network measures VerisAI's access and not that provider's — and a site that correctly allows the verified crawler may well refuse the imitation.
How to block or ask about the scanner
To block VerisAI's generic technical requests, create a WAF or firewall rule that matches the exact User-Agent shown above. This blocks the generic technical portion of the assessment.
For questions, retention requests, or a request to suppress future VerisAI assessments for a domain, email support@verisai.eu with the domain and relevant log timestamp.