COMPANY

Insider risk is the last mile of security.

For twenty years, the industry poured its budget into the perimeter and the endpoint signature. Behavior was for somebody else to solve. Vedric exists because behavior is the threat surface - and nobody had finished building for it.

01
CONVICTION

An essay on why we're building what we're building.

he last twenty years of enterprise security have been a perimeter story. Build walls. Watch the doors. Scan every binary that arrives. It worked - for the threat class the industry was organized around. External attackers. Known-bad signatures. Credentials stolen from outside.

02

The shape that didn't fit that story is insider risk. An insider has valid credentials, valid access, and a valid reason to be on your systems - until the exact moment they don't.

SIEM aggregates their logs into noise. EDR watches their processes but has no memory of what's normal for them. UEBA scores their authentication events but can't see what they do after they log in. The endpoint is where the behavior happens; the endpoint is where the existing tools stop looking.

“Behavior is the threat surface - and nobody had finished building for it.”
03

That gap has been acceptable as long as nobody was paying attention. The last few years have made it un-acceptable.

Data egress incidents are no longer external. Regulated industries are being asked, by their own auditors, how they would see an insider preparing to leave with material. The honest answer, for most programs, is we wouldn't. Vedric exists to replace that answer with something you could say out loud.

“We treat the forensic audit as a non-negotiable.”
04

We refuse to collect content because insider-risk detection doesn't need content, and the industry's history with “we'll just collect everything and sort it later” has been ugly.

We sign every message, audit every write, and enforce tenant isolation at the query layer, because those are the constraints an insider-risk platform should have been built with from the start.

- Vedric, 2026

02 / MEET THE FOUNDER
Ahmad Haji, founder of Vedric

Ahmad Haji

FOUNDER

ahmad@vedric.io

I designed and built Vedric end to end - the Windows agent, the detection engine, the backend, the triage layer, and the console you run it from.

Every refusal on the previous page - metadata over content, no keystrokes, no screenshots, no message bodies - was decided at the foundation, before there was any commercial pressure to loosen it. That is the point. Those limits are not policy that a future quarter can quietly revise; they are written into the agent, where the code has no path that reads a file's contents or activates a camera. Not disabled - absent.

Vedric is early and growing, and that standard is the one anyone who joins builds to. It is far easier to hold a line that was drawn before the first customer than to claw one back afterwards, which is why most platforms in this category never do.

It also means you deal with the people who actually build the thing. Raise an edge case and it reaches an engineer who knows the code path you are asking about, and a fix ships when it is ready.

Buying security software means trusting someone's judgment about what to collect and what to leave alone. Here you can see exactly whose judgment set it.

Ask me anything, directly: ahmad@vedric.io

03 / THREE PRINCIPLES

How Vedric is structurally different.

01 /

Behavior over signatures

Insider activity is almost always novel. A signature-based catalog can't describe it. The right signal is the gap between what a user does today and what they've done for months - and what their peers do - and what the system has never seen them do before.

02 /

Privacy enforced by design

Vedric minimizes content at the source: no screens, keystrokes, file payloads, or message bodies. A bounded, redacted PowerShell script preview is the documented exception, and host-policy management is explicit opt-in.

03 /

Built around the operator

AI triage is one component. The product is the forensic audit and correlated storyline; remote response is a default-off preview. Detection has to work when the model is offline. It does.

04 / WHY OTHERS MISS

What each tool class does well - and where it ends.

SIEM

Aggregates events across the environment. Good at queryable history and compliance. No behavioral memory. Correlation is left to the analyst.

EDR

Watches processes on the endpoint. Catches known-bad patterns. Has no per-user baseline, no peer context, no multi-day storyline memory.

UEBA

Scores user behavior from log aggregation. Reads identity and auth layer well. Doesn't see the host layer where the behavioral shape actually lives.

DLP

Watches content flow at predefined egress points. Catches policy violations on specific document types. Insider behavior that doesn't touch content policies flies past it.

05 / PRIVACY, ANCHORED

The refusal list, in writing.

PRIVACY RECEIPT
issued at agent install · re-verified per collector pass
COLLECTED
  • Process + parent-process metadata
  • Command-line activity
  • Authentication events
  • Network destinations (IPs, domains)
  • File activity metadata (counts, types)
  • Endpoint health + heartbeat
REFUSED
  • File contents
  • Keystrokes
  • Screen contents / screenshots
  • Email and chat message bodies
  • Document bodies
  • Browser content / page source
Enforced in code, not policy.
agent-side · cannot be extended remotely

Work with us.

We hire security, backend, frontend, and go engineers. We work with design partners on specific insider-risk programs. We take calls from analyst firms and compliance leads.