Vedric is an agent, a cloud, and an operator surface - connected by signed messages and tenant-isolated at every layer. Nothing collected is content. Nothing executed goes unlogged. Nothing written can be quietly undone.
Runs as a managed service under OS-sealed credentials. Collects primarily behavioural metadata from the host, identity, and network layers, plus a documented bounded PowerShell script preview where host logging is enabled.
Baselines behavior per user and per peer group, correlates deviations into storylines, and runs triage against a strict budget. Every query is tenant-scoped. If the AI layer is unavailable, baseline detection keeps running.
Your analyst can correlate related activity into storylines. Remote response commands are admin-gated, reason-required, signed, and audited, but remain default-off pending deployment-specific safety drills.
Runs as a managed service under OS-sealed credentials. Collects primarily behavioural metadata from the host, identity, and network layers, plus a documented bounded PowerShell script preview where host logging is enabled.
Baselines behavior per user and per peer group, correlates deviations into storylines, and runs triage against a strict budget. Every query is tenant-scoped. If the AI layer is unavailable, baseline detection keeps running.
Your analyst can correlate related activity into storylines. Remote response commands are admin-gated, reason-required, signed, and audited, but remain default-off pending deployment-specific safety drills.
The refusal list lives in the agent source. PowerShell script previews are the one bounded exception: they require host logging, are truncated and scrubbed, and machine-policy management is opt-in.
Every tenant-scoped query is automatically filtered. The guarantee is tested on every build - if a new table would create a cross-tenant path, the build fails.
Agent binaries are signed with a key that never lives on the server. A cloud compromise alone cannot produce a valid update; the attacker would need offline key custody too.
The application database role is refused edits and deletes on audit rows. Customers with a database-owner or infrastructure-admin threat model should also retain exports in an independently controlled system.
Triage runs behind a fail-closed control layer: if the check that decides whether AI may be used cannot be completed, it resolves to no. An admin can disable AI triage for their whole organization, and an operator kill-switch propagates across the platform quickly. Baseline behavioral detection continues regardless - the AI layer is useful, not load-bearing.
Remote commands require an admin role and written reason and use a signed channel, but remain disabled until deployment-specific endpoint and recovery drills are complete.