Persistence + staged collection sequence
endpoint-042 · corporate device
Your perimeter is guarded. The inside is trusted - until it isn't. Vedric learns each user's baseline and flags the behavioral drift that EDR, SIEM, and UEBA miss.
endpoint-042 · corporate device
PRIVACY ENFORCED IN CODE · NOT PROMISED IN MARKETING
No keystrokes, screenshots, or file content. Those code paths do not exist in the agent.
Every agent message is cryptographically signed - tamper-evident from endpoint to cloud.
Three independent, database-enforced audit logs. Nothing rewrites the past.
Per-tenant keys and scoped queries, verified by build-time isolation tests.
Now selecting a small group of design partners. If insider risk is on your roadmap this year, we should talk.
This is a composite of behavioral shapes Vedric reads in the run-up to a departure. It's one kind of anomaly - not the only one we catch. Identifying details removed. Specific thresholds stay inside the product.
Vedric's baseline engine doesn't know the difference between malicious, accidental, and automated. It knows the difference between normal and not. That's what makes it useful across the three shapes most incidents actually take.
A trusted user misconfigures a bulk share. Terabytes begin syncing to an unintended destination. No malicious intent. The destination is not on any blocklist. Vedric doesn't need malicious intent - the deviation from this user's own baseline is the signal.
A legitimate background task (a scheduled backup, a CI runner, a maintenance script) starts doing something outside its shape. New destination, different access, elevated frequency. Vedric baselines per-process, not just per-user. When a service breaks character, Vedric notices.
Valid credentials, normal login. But once past the door, the behavior doesn't match the legitimate user - different access pattern, different timing, different scope. Vedric compares against the user's own baseline, so a compromised account looks nothing like its owner.
"Show me how you would have seen it if a resigning employee had been preparing to leave with material for two weeks."
Most security programs cannot answer that question. Their tools are built around external attackers, known-bad indicators, or aggregated log scoring. Insider rehearsal falls in the gap between them. Vedric is built for the gap.
Watching people prepare to betray you doesn't require reading their email. It requires watching behavior. Vedric is built around that distinction - and enforces it at the source code of the agent, not in a policy PDF.
Get ahead of the question your auditor, your board, and your CEO will eventually ask. Thirty-minute scoping call. No slides.