COMPANY

Insider risk is the last mile of security.

For twenty years, the industry poured its budget into the perimeter and the endpoint signature. Behavior was for somebody else to solve. Vedric exists because behavior is the threat surface - and nobody had finished building for it.

01
CONVICTION

An essay on why we're building what we're building.

he last twenty years of enterprise security have been a perimeter story. Build walls. Watch the doors. Scan every binary that arrives. It worked - for the threat class the industry was organized around. External attackers. Known-bad signatures. Credentials stolen from outside.

02

The shape that didn't fit that story is insider risk. An insider has valid credentials, valid access, and a valid reason to be on your systems - until the exact moment they don't.

SIEM aggregates their logs into noise. EDR watches their processes but has no memory of what's normal for them. UEBA scores their authentication events but can't see what they do after they log in. The endpoint is where the behavior happens; the endpoint is where the existing tools stop looking.

“Behavior is the threat surface - and nobody had finished building for it.”
03

That gap has been acceptable as long as nobody was paying attention. The last few years have made it un-acceptable.

Data egress incidents are no longer external. Regulated industries are being asked, by their own auditors, how they would see an insider preparing to leave with material. The honest answer, for most programs, is we wouldn't. Vedric exists to replace that answer with something you could say out loud.

“We treat the forensic audit as a non-negotiable, not a feature.”
04

We are building a platform, not a product. We refuse to collect content because insider-risk detection doesn't need content, and the industry's history with “we'll just collect everything and sort it later” has been ugly.

We sign every message, audit every write, and enforce tenant isolation at the query layer - not because anyone asked us to, but because those are the constraints an insider-risk platform should have been built with from the start.

- Vedric, 2026

02 / THREE PRINCIPLES

How Vedric is structurally different.

01 /

Behavior over signatures

Insider activity is almost always novel. A signature-based catalog can't describe it. The right signal is the gap between what a user does today and what they've done for months - and what their peers do - and what the system has never seen them do before.

02 /

Privacy enforced by design

The easiest way to handle content safely is to never have it. Vedric collects behavioral metadata only, enforced at the agent's collector interface. The list of things we refuse to see is in code, not in a PDF.

03 /

Operator-centered, not AI-centered

AI triage is a useful component, not the product. The product is the forensic audit, the correlated storyline, the signed response action. Detection has to work when the model is offline. It does.

03 / WHY OTHERS MISS

What each tool class does well - and where it ends.

SIEM

Aggregates events across the environment. Good at queryable history and compliance. No behavioral memory. Correlation is left to the analyst.

EDR

Watches processes on the endpoint. Catches known-bad patterns. Has no per-user baseline, no peer context, no multi-day storyline memory.

UEBA

Scores user behavior from log aggregation. Reads identity and auth layer well. Doesn't see the host layer where the behavioral shape actually lives.

DLP

Watches content flow at predefined egress points. Catches policy violations on specific document types. Insider behavior that doesn't touch content policies flies past it.

04 / PRIVACY, ANCHORED

The refusal list, in writing.

PRIVACY RECEIPT
issued at agent install · re-verified per collector pass
COLLECTED
  • Process + parent-process metadata
  • Command-line activity
  • Authentication events
  • Network destinations (IPs, domains)
  • File activity metadata (counts, types)
  • Endpoint health + heartbeat
REFUSED
  • File contents
  • Keystrokes
  • Screen contents / screenshots
  • Email and chat message bodies
  • Document bodies
  • Browser content / page source
Enforced in code, not policy.
agent-side · cannot be extended remotely

Work with us.

We hire security, backend, frontend, and go engineers. We work with design partners on specific insider-risk programs. We take calls from analyst firms and compliance leads.