BEHAVIORAL INSIDER-RISK DETECTION

See insider risk before it becomes damage.

Your perimeter is guarded. The inside is trusted - until it isn't. Vedric learns each user's baseline and flags the behavioral drift that EDR, SIEM, and UEBA miss.

Metadata-only - no content Windows today
VEDRIC · LIVE DETECTION MONITORING
2026-04-22 18:42 UTC
STORY-7F3A
HIGH

Persistence + staged collection sequence

endpoint-042 · corporate device

source: endpoint telemetry·pattern: off-baseline sequence·correlated: 14 events
PersistenceCollection
14-DAY REHEARSALpre-departure window
VEDRIC
11
EDR/SIEM
0

PRIVACY ENFORCED IN CODE · NOT PROMISED IN MARKETING

Metadata only

No keystrokes, screenshots, or file content. Those code paths do not exist in the agent.

Signed wire

Every agent message is cryptographically signed - tamper-evident from endpoint to cloud.

Append-only audit

Three independent, database-enforced audit logs. Nothing rewrites the past.

Tenant-isolated

Per-tenant keys and scoped queries, verified by build-time isolation tests.

Now selecting a small group of design partners. If insider risk is on your roadmap this year, we should talk.

ONE SCENARIO · THE REHEARSAL

Fourteen days of signal. Eleven chances to act.

This is a composite of behavioral shapes Vedric reads in the run-up to a departure. It's one kind of anomaly - not the only one we catch. Identifying details removed. Specific thresholds stay inside the product.

  1. DAY 01
    Normal. Shipping code on the same projects they've owned for two years.
    baseline · no signal
    -
  2. DAY 03
    First off-baseline activity shape. Query pattern outside their six-month norm.
    deviation logged · not yet alerting
    VEDRIC
  3. DAY 05
    Access scope drifts outside assigned project scope. Same credentials. Different behavior.
    scope drift · correlated with day 03
    VEDRIC
  4. DAY 06
    Normal working-hours activity. No further drift.
    watching
    -
  5. DAY 08
    Off-hours activity increases. Files touched during a window the user never worked in before.
    temporal deviation
    VEDRIC
  6. DAY 09
    Storyline correlated. Three deviations, same user, same endpoint, six days.
    storyline materialized
    VEDRIC
  7. DAY 10
    Normal. User takes a half-day off.
    watching
    -
  8. DAY 11
    Privileged query not run in the last six months. Legitimate access - but not legitimate timing.
    privilege drift
    VEDRIC
  9. DAY 12
    Access to repository areas outside their current team.
    scope drift, second instance
    VEDRIC
  10. DAY 13
    Egress volume above their personal baseline, during hours they don't normally work.
    exfiltration-shaped pattern
    VEDRIC
  11. DAY 14
    Employee submits resignation notice. HR is told. Their laptop is on the forfeit list.
    (Vedric had eleven days of warning)
    -
VEDRIC SAW
11 / 14
days of correlated behavioral drift before the resignation meeting was on anyone's calendar.
YOUR CURRENT STACK SAW
0 / 14
days. SIEM aggregates events, EDR watches processes, UEBA scores logins. None of them correlate endpoint behavior over time against the user's own baseline.
BEYOND INTENT

A deviation is a deviation - regardless of who caused it.

Vedric's baseline engine doesn't know the difference between malicious, accidental, and automated. It knows the difference between normal and not. That's what makes it useful across the three shapes most incidents actually take.

01 /ACCIDENT

The honest mistake

A trusted user misconfigures a bulk share. Terabytes begin syncing to an unintended destination. No malicious intent. The destination is not on any blocklist. Vedric doesn't need malicious intent - the deviation from this user's own baseline is the signal.

02 /AUTOMATION

The drifting process

A legitimate background task (a scheduled backup, a CI runner, a maintenance script) starts doing something outside its shape. New destination, different access, elevated frequency. Vedric baselines per-process, not just per-user. When a service breaks character, Vedric notices.

03 /COMPROMISE

The borrowed account

Valid credentials, normal login. But once past the door, the behavior doesn't match the legitimate user - different access pattern, different timing, different scope. Vedric compares against the user's own baseline, so a compromised account looks nothing like its owner.

THE GAP

The question your auditor is already asking.

"Show me how you would have seen it if a resigning employee had been preparing to leave with material for two weeks."

Most security programs cannot answer that question. Their tools are built around external attackers, known-bad indicators, or aggregated log scoring. Insider rehearsal falls in the gap between them. Vedric is built for the gap.

WHAT WE SEE - AND REFUSE TO SEE

What Vedric sees.
What Vedric refuses to see.

Watching people prepare to betray you doesn't require reading their email. It requires watching behavior. Vedric is built around that distinction - and enforces it at the source code of the agent, not in a policy PDF.

PRIVACY RECEIPT
issued at agent install · re-verified per collector pass
COLLECTED
  • Process + parent-process metadata
  • Command-line activity
  • Authentication events
  • Network destinations (IPs, domains)
  • File activity metadata (counts, types)
  • Endpoint health + heartbeat
REFUSED
  • File contents
  • Keystrokes
  • Screen contents / screenshots
  • Email and chat message bodies
  • Document bodies
  • Browser content / page source
Enforced in code, not policy.
agent-side · cannot be extended remotely

Don’t be the CISO who finds out in court.

Get ahead of the question your auditor, your board, and your CEO will eventually ask. Thirty-minute scoping call. No slides.

Join the waitlistTalk to security teamResponse within one business day.