How Stoffel Secures Its MPC Stack with Veria

Stoffel

How Stoffel swapped six-figure, weeks-long security reviews for Veria, and got better findings in hours.

Stoffel

About Stoffel

Stoffel Labs is building privacy tools to empower developers to build privacy-first apps without compromise. Stoffel’s stack consists of a programming language, Stoffel-Lang, a virtual machine, StoffelVM and an MPC library focused on robust multiparty computation protocols.

The Challenge: Keeping Up with Engineering

Mikerah and the team at Stoffel maintain every layer of their stack: the programming language (Stoffel-Lang), the virtual machine (StoffelVM), and the MPC library (mpc-protocols). That’s a lot of surface area for vulnerabilities to hide in.

Before Veria, the team relied on reputable third-party audit firms for one-time code reviews. The process was slow by design: contract an auditor, wait weeks for the review, then remediate findings. That meant unreviewed code was regularly pushed in the windows between audits.

We paid roughly 6 figures for an audit from a top security firm. Veria costs us significantly less and found the same bugs and more.
Mikerah — Founder of Stoffel Labs

Traditional static scanners would generate excessive false positives and create manual triage work for the team.

They needed a way to continuously monitor for vulnerabilities and catch them before they ever reached prod.

The Solution: Why Veria Came Out on Top

Since partnering with Veria Labs, the Stoffel team has consistently received high-quality, actionable findings.

Vs. Human Auditors

Compared head-to-head with a leading third-party audit firm, Veria found the same vulnerabilities while being significantly faster. Instead of waiting 2-3 weeks and paying over six figures, the team had findings in 2-3 hours.

Veria’s findings were actually better than the audit firm’s: it matched every critical and high severity finding, and surfaced an additional medium the firm missed.

Additionally:

  • Full Coverage: Instead of paying for a narrow audit scope, Veria covers 100% of Stoffel’s stack. Every repo. Every line of code.
  • Flexibility: When a new feature needs to ship fast, the team triggers a scan on the spot and has results the same day. No waiting on a human auditor.
  • Fast Remediation: Every finding comes with a clear description, an impact and severity assessment, and remediation suggestions, so the Stoffel team spends less time triaging and more time building.

Vs. Existing Security Tooling

  • Quality of Findings: Unlike existing SAST tools, Veria uncovers real vulnerabilities that respect the business logic of the application. It goes well beyond traditional pattern matching to surface vulnerabilities that matter.
  • False Positive Rates: In a direct comparison with GitHub Advanced Security and another AI-native SAST, Veria significantly outperformed both, sparing the team endless hours of triage.
Veria GitHub Advanced Security
# of Bugs 34 6
False Positive % 5% 100%

Today, the team uses Veria heavily, especially when large chunks of work have been completed and need a thorough review before shipping.

About Veria Labs

At Veria Labs, we build Veria, an autonomous pentester that finds, proves, and helps fix security vulnerabilities in your application. Founded by members of the #1 US hacking team, we’ve found critical vulnerabilities in every company we’ve worked with, from small startups to enterprise giants.

Think we can help secure your systems? We’d love to chat! Book a call here.