There is a real reason security and compliance teams care about risky behavior from valid accounts. There is also a real reason most employees do not want their screens recorded. Vedric is built for the first problem and explicitly rejects the second.
THE PROBLEM
Most "employee monitoring" tools were built for a different decade. Screen recording. Keystroke capture. Webcam check-ins. Screenshot timelines that end up sitting in a vendor cloud. They produce content nobody wants to be responsible for, generate liability instead of resolving it, and rarely answer the actual question: is the behavior of this account drifting outside its pattern?
Reading screens and keystrokes captures sensitive information you did not ask for and now have to defend. Once that data exists, every breach scenario becomes worse.
Visible surveillance changes how the organization works. Productivity-positive employees treat it as evidence of distrust; the actually-risky behavior simply moves to channels you do not see.
Many jurisdictions restrict monitoring. EU works councils, Quebec privacy law, several U.S. states with biometric-data statutes - content-level employee monitoring carries real legal exposure.
Even when surveillance is permitted, video and keystrokes do not give you the answer you actually need: is this account behaving like itself? That is a per-user behavioral question, not a content question.
Vedric reads endpoint metadata only: process, command, authentication, network, file, and DNS surfaces. The agent does not have screen, keystroke, microphone, or webcam collectors in its codebase. Behavioral detection is the entire point; content collection is a different product, and we deliberately did not build it.
The collector reads how processes spawn, what commands run, when the user is active, and what destinations are touched. It does not read what is on the screen, what was typed, or what files contain.
Detection compares the user against their own pattern, not a moralistic threshold. A junior analyst who works late occasionally is not flagged for that alone - until it correlates with other off-baseline behavior into a storyline.
Tenant admins can read the full storyline and audit trail for any primary identity in their tenant. The platform does not have a hidden surveillance layer reserved for "really sensitive" employees.
EXAMPLE SCENARIO · TIMELINE
No malware. No policy breach by traditional rules. A finance team member quietly begins to do their job differently - and that is the signal.
The behavioral pattern was the entire signal. The platform never collected anything that would be uncomfortable to defend in front of a works council, a regulator, or the employee in question.
Employee risk monitoring usually means surveillance. Vedric is a deliberate counterexample: behavioral detection at the endpoint, with the surveillance collectors removed at the source code of the agent - not behind a feature flag.
Read the full privacy stance →Early access is for teams who need answers about behavioral risk and refuse to build a surveillance liability surface to get them.