EMPLOYEE RISK · WITHOUT SURVEILLANCE

Risk monitoring is a behavioral question. Surveillance is the wrong answer.

There is a real reason security and compliance teams care about risky behavior from valid accounts. There is also a real reason most employees do not want their screens recorded. Vedric is built for the first problem and explicitly rejects the second.

Request Early AccessView PlatformWindows endpoints today.

THE PROBLEM

The cheap answer is surveillance. The right answer is behavior.

Most "employee monitoring" tools were built for a different decade. Screen recording. Keystroke capture. Webcam check-ins. Screenshot timelines that end up sitting in a vendor cloud. They produce content nobody wants to be responsible for, generate liability instead of resolving it, and rarely answer the actual question: is the behavior of this account drifting outside its pattern?

WHY CURRENT APPROACHES FALL SHORT

Why surveillance-shaped tools backfire.

CONTENT-CENTRIC

Reading screens and keystrokes captures sensitive information you did not ask for and now have to defend. Once that data exists, every breach scenario becomes worse.

TRUST-DAMAGING

Visible surveillance changes how the organization works. Productivity-positive employees treat it as evidence of distrust; the actually-risky behavior simply moves to channels you do not see.

LEGALLY EXPOSED

Many jurisdictions restrict monitoring. EU works councils, Quebec privacy law, several U.S. states with biometric-data statutes - content-level employee monitoring carries real legal exposure.

NO BEHAVIORAL SIGNAL

Even when surveillance is permitted, video and keystrokes do not give you the answer you actually need: is this account behaving like itself? That is a per-user behavioral question, not a content question.

HOW VEDRIC HELPS

Behavioral detection where surveillance does not belong.

Vedric reads endpoint metadata only: process, command, authentication, network, file, and DNS surfaces. The agent does not have screen, keystroke, microphone, or webcam collectors in its codebase. Behavioral detection is the entire point; content collection is a different product, and we deliberately did not build it.

01 /METADATA-ONLY

Behavioral signal at the endpoint

The collector reads how processes spawn, what commands run, when the user is active, and what destinations are touched. It does not read what is on the screen, what was typed, or what files contain.

02 /BASELINE

The user, against themselves

Detection compares the user against their own pattern, not a moralistic threshold. A junior analyst who works late occasionally is not flagged for that alone - until it correlates with other off-baseline behavior into a storyline.

03 /AUDITABLE

Visible to the people being scored

Tenant admins can read the full storyline and audit trail for any primary identity in their tenant. The platform does not have a hidden surveillance layer reserved for "really sensitive" employees.

EXAMPLE SCENARIO · TIMELINE

A finance employee whose work pattern shifts.

No malware. No policy breach by traditional rules. A finance team member quietly begins to do their job differently - and that is the signal.

  1. T+01
    T+01 - typical month-end pattern: same systems, same hours, same query shapes. Baseline accumulates.
  2. T+02
    T+12 - first deviation logged. A query against a partner finance system the user has not touched in months. Single event, low confidence.
  3. T+03
    T+15 - second deviation. File access shape on month-old material outside the current cycle.
  4. T+04
    T+18 - temporal deviation. Activity outside the user historical hours window.
  5. T+05
    T+19 - multiple correlated deviations. Storyline materializes. Single alert reaches the analyst with the full chain.
  6. T+06
    T+20 - admin reviews with HR. Storyline is the surface, not a screen recording, not a keystroke log, not a webcam still.
OUTCOME

The behavioral pattern was the entire signal. The platform never collected anything that would be uncomfortable to defend in front of a works council, a regulator, or the employee in question.

WHAT VEDRIC SURFACES

What we look at - and what we deliberately do not.

VEDRIC SURFACES
  • Process and command-line metadata across the user behavioral surfaces
  • File access patterns by system, time, and volume - not file contents
  • Authentication and access-cadence drift against the user own baseline
  • Network destination patterns - not packet payloads
  • Per-user, per-peer, per-endpoint baselines feeding correlated storylines
VEDRIC DOES NOT DO
  • Capture keystrokes
  • Take screenshots or screen recordings
  • Activate webcam or microphone
  • Inspect file contents or private message content
  • Track productivity metrics, idle time, or activity scores
PRIVACY-FIRST BY DEFAULT

No keystrokes. No screenshots. No file contents.

Employee risk monitoring usually means surveillance. Vedric is a deliberate counterexample: behavioral detection at the endpoint, with the surveillance collectors removed at the source code of the agent - not behind a feature flag.

Read the full privacy stance →
  • No keystrokes
  • No screenshots
  • No webcam
  • No microphone
  • No file contents
  • No private messages
FREQUENTLY ASKED

Questions buyers ask first.

Risk visibility without surveillance liability.

Early access is for teams who need answers about behavioral risk and refuse to build a surveillance liability surface to get them.

Request Early AccessTalk to security teamResponse within one business day.