MSPs need to detect insider risk for a fleet of unrelated client environments, with full tenant isolation, no shared models, no shared blast radius, and no invasive collectors. Vedric was built multi-tenant and metadata-only from the first commit.
THE PROBLEM
An MSP that lights up surveillance-grade collectors across client environments inherits the legal and reputational risk of every client at once. A breach of MSP-collected content data is several breaches in one. Yet MSPs need real visibility into client behavior, not just patch status. The way out is metadata-only behavioral detection, with hard tenant isolation enforced everywhere it matters.
Many "multi-tenant" tools are single-tenant tools with a tenant_id column. Models are shared. Aggregation queries are shared. A noisy client distorts detection for the rest. MSPs need real isolation at every layer.
Tools that capture screens, keystrokes, or file contents create a liability surface that scales with the number of clients. One MSP-side breach is a multi-client incident.
Threshold-based stacks generate fatigue at one tenant; multiplied across a fleet they become unreviewable. MSPs need correlated storylines, not raw events.
A baseline trained across all tenants is not a baseline. It is a smoothed average that catches almost nothing. Per-tenant per-user baselines are the only way to read drift on each client.
Vedric is a multi-tenant platform from the data layer up. Every collected event, every baseline, every storyline, every AI tool call is scoped to one tenant. There is no cross-tenant query path. There is no shared model. The MSP operator sees client environments as separate spaces with separate audit trails.
Telemetry, baselines, storylines, and AI tool calls are all tenant-scoped. The platform does not run cross-tenant analytics, does not share peer baselines across tenants, and does not allow one client environment to influence another's detection.
The agent does not capture screens, keystrokes, audio, or file contents. The MSP operator does not inherit a content-data liability surface that scales with clients.
The MSP operator sees a per-tenant storyline view and an aggregate fleet view that shows storyline counts and severity per client without crossing into per-tenant content. Each tenant's admin can read their own audit trail.
EXAMPLE SCENARIO · TIMELINE
The MSP runs Vedric across 40 client tenants. Per-client baselines have matured. The fleet view shows quiet activity across most tenants and one storyline that materialized overnight on a specific client.
The MSP saw one signal across 40 clients without inheriting any client's content liability. The client got a complete, exportable storyline that survived the handoff intact.
Vedric is metadata-only by design. The collector enforces these limits at the source code of the agent.
Read the full privacy stance →Early access is offered to MSPs running production Windows fleets across multiple client environments who want behavioral visibility without inheriting a content liability surface.