PLATFORM

Built around the endpoint. Verified at every hop.

Vedric is an agent, a cloud, and an operator surface - connected by signed messages and tenant-isolated at every layer. Nothing collected is content. Nothing executed goes unlogged. Nothing written can be quietly undone.

01 / ARCHITECTURE

Three layers. One signed channel between them.

E
ENDPOINT
SIGNED CHANNEL
01 /ENDPOINT

The agent

Runs as a managed service under OS-sealed credentials. Collects primarily behavioural metadata from the host, identity, and network layers, plus a documented bounded PowerShell script preview where host logging is enabled.

content-minimizing collection
offline-capable · catches up on reconnect
signed over the wire
C
CLOUD
SIGNED CHANNEL
02 /CLOUD

The correlator

Baselines behavior per user and per peer group, correlates deviations into storylines, and runs triage against a strict budget. Every query is tenant-scoped. If the AI layer is unavailable, baseline detection keeps running.

per-user and per-peer baselines
tenant-isolated throughout
triage behind a fail-closed budget
O
OPERATOR
03 /OPERATOR

The surface

Your analyst can correlate related activity into storylines. Remote response commands are admin-gated, reason-required, signed, and audited, but remain default-off pending deployment-specific safety drills.

one alert per storyline
admin-gated response · reason required
audit-first by default
02 / DETECTION SEQUENCE

How a deviation becomes a signed verdict.

  1. 01 /
    Collect
    Endpoint behavior is collected across several surfaces by default. Deeper visibility modes can be enabled per tenant. What is never collected is documented and refused in code.
  2. 02 /
    Normalize
    User identity is anonymized on the endpoint. The backend stores a per-machine one-way token, not the raw identity. Your team can label that token after an independent local investigation; Vedric cannot reverse it.
  3. 03 /
    Detect
    Two layers run in parallel. Behavioral baselines (per user, per peer cohort, per endpoint) surface drift from the user's own pattern. Rule-based detection catches well-known-bad patterns that fire from day one. A quiet warm-up prevents the baseline layer from generating noise while it settles; the rule layer is active immediately.
  4. 04 /
    Correlate
    Deviations and rule hits on the same endpoint and user within a short window become a single correlated storyline.
  5. 05 /
    Triage
    Triage runs inside a fail-closed budget and circuit. It reads tenant-scoped data only and never reaches the endpoint. If it is unavailable for any reason, baseline detection continues.
  6. 06 /
    Respond
    Remote response is a default-off preview. Its command paths are admin-gated, reason-required, signed, and audited, but they remain unavailable until the deployment passes endpoint safety and recovery drills.
  7. 07 /
    Archive
    Every decision lands in an append-only audit. Edits and deletes are refused at the storage layer. Your forensic trail is preserved without depending on operator discipline.
03 / BUILT WITH

Six constraints the product is built around.

Content-minimizing collection

The refusal list lives in the agent source. PowerShell script previews are the one bounded exception: they require host logging, are truncated and scrubbed, and machine-policy management is opt-in.

Tenant isolation by default

Every tenant-scoped query is automatically filtered. The guarantee is tested on every build - if a new table would create a cross-tenant path, the build fails.

Offline-signed updates

Agent binaries are signed with a key that never lives on the server. A cloud compromise alone cannot produce a valid update; the attacker would need offline key custody too.

Append-only audit

The application database role is refused edits and deletes on audit rows. Customers with a database-owner or infrastructure-admin threat model should also retain exports in an independently controlled system.

Fail-closed AI

Triage runs behind a fail-closed control layer: if the check that decides whether AI may be used cannot be completed, it resolves to no. An admin can disable AI triage for their whole organization, and an operator kill-switch propagates across the platform quickly. Baseline behavioral detection continues regardless - the AI layer is useful, not load-bearing.

Default-off response preview

Remote commands require an admin role and written reason and use a signed channel, but remain disabled until deployment-specific endpoint and recovery drills are complete.

See the platform in a real environment.

Join the waitlistTalk to security teamResponse within one business day.