ENGAGEMENT

Priced to your deployment. Scoped to your environment.

Vedric is sold through a scoping conversation, not a pricing page. What you need from the product - endpoint count, collector tier, audit retention, support arrangement - changes what we build together. We'd rather talk than guess.

01 / WHY WE DON'T LIST PRICES

The deployment shape changes the spec more than endpoint count does.

A 500-endpoint SaaS deployment and a 500-endpoint VPC-isolated deployment are different products in almost every way that matters: where data lives, who controls the keys, what audit retention looks like, how response actions flow. A single list price would hide all of that.

Insider-risk buyers deserve a conversation.

Security programs buying insider-risk detection aren't comparing SKUs - they're mapping coverage to their threat model. We'd rather spend thirty minutes understanding that than publish a table of tiers everyone would ignore anyway.

02 / DEPLOYMENT SHAPES

Three places your detection data can live.

AVAILABLE

SaaS

Security teams who want the fastest path to coverage on Vedric's managed cloud.

DATA LIVES
Vedric's managed cloud. User identities are anonymized at the agent. Metadata only.
DEPLOYMENT
Logically isolated per tenant. Configurable audit retention. Enterprise SAML SSO.
SUPPORT
Direct-to-engineering during early access. Response within one business day.
DESIGN PARTNERS

VPC-Isolated

Regulated environments where data residency and key custody are part of scoping.

DATA LIVES
Architecture co-designed. Outbound egress for AI triage is opt-in and disclosed.
DEPLOYMENT
Discussed during scoping. Key handling, audit retention, and infrastructure shape are part of the design.
SUPPORT
Named engineering contact. Response arrangement agreed during scoping.
ON REQUEST

On-Premises

Defense, intelligence, critical infrastructure - anywhere detection data cannot leave your perimeter.

DATA LIVES
Your hardware, your network, your keys.
DEPLOYMENT
Customer-operated. Vedric provides signed binaries and deployment guidance. Architecture is co-designed during scoping.
SUPPORT
Remote deployment support. Engineering contact. Update cadence agreed during scoping.

VPC-Isolated and On-Premises shapes are co-designed with security teams during scoping rather than offered as off-the-shelf SKUs. If your environment requires either, the scoping call is the right place to map it out.

03 / HOW ENGAGEMENT WORKS

From scoping call to production, in five steps.

  1. 01 /
    Scoping call
    30 minutes. We map your threat model, deployment shape, endpoint count, and constraints. You leave with a yes/no on whether Vedric is a fit and what the pilot would look like.
  2. 02 /
    Design review
    A written deployment proposal - architecture, collectors, retention, SSO, key handling. Your security and compliance teams review. We iterate until it's right.
  3. 03 /
    Pilot deployment
    A scoped rollout to a subset of your endpoints. The agent installs, baselines settle, detection begins. Your team gets a named contact and a regular check-in cadence agreed during scoping.
  4. 04 /
    Production rollout
    Phased to your full endpoint fleet. Alerting thresholds, peer clusters, and response policies are tuned against pilot data.
  5. 05 /
    Ongoing tuning
    Periodic coverage reviews. New collectors as they ship. Gap analysis against your evolving threat model.
04 / OPERATIONAL QUESTIONS

The ones security teams actually ask.

Where does detection data live?

Depends on deployment shape. SaaS: Vedric's managed cloud. VPC: your VPC. On-prem: your datacenter. We're explicit about this on the deployment page above.

What's collected. What's never collected.

Collected: behavioural metadata across the host, identity, and network layers. Never collected: file contents, keystrokes, screenshots, email bodies, document bodies, browser page content. The refusal list is enforced in the agent source code; the specific collector mix is part of scoping and is not documented publicly.

What operating systems does the agent run on?

Windows 10, Windows 11, and Windows Server 2016+ today. Linux and macOS are on the roadmap; current timelines are shared under NDA during scoping.

Can we bring our own SSO?

Yes. Enterprise SAML 2.0 SSO is supported with any compliant IdP - Okta, Entra ID, Google Workspace, and others. SCIM-based automated user provisioning is on the roadmap; today, user provisioning happens at first sign-in via JIT.

What happens when the agent goes offline?

It buffers locally and catches up when connectivity returns. The server marks an endpoint offline after a quiet window; that alone is not a security signal.

How does AI triage stay under budget?

Triage runs inside a strict per-tenant daily budget and a fail-closed control layer. If the AI layer is unavailable for any reason - outage, exhausted budget, or an operator toggle - baseline behavioral detection keeps running without it.

04A / SHAPE COMPARISON

The same product, sized to where your data has to live.

A side-by-side on the dimensions security and procurement teams ask about most. Specifics are confirmed in scoping.

AVAILABLE
SaaS
DESIGN PARTNERS
VPC-Isolated
ON REQUEST
On-Prem
DATA RESIDENCY
Vedric cloud · US or EU region
Your VPC · region of your choice
Your datacenter · zero external egress
RETENTION DEFAULT
90-day rolling
Configured during scoping
Customer-controlled
KEY CUSTODY
Vedric-managed · per-tenant isolation
Co-custody · scoping-defined
Customer-held · binaries arrive signed
SSO
Enterprise SAML 2.0
Enterprise SAML 2.0
Enterprise SAML 2.0 · or local IdP
SLA TIER
Standard · 1 business day
Named engineering contact
Negotiated during scoping
DEPLOYMENT TIMELINE
Days
Weeks
Engaged scoping

On mobile the columns stack - read each shape top-to-bottom rather than across.

05 / PRICE ANCHOR

Pilots typically scope between $8 and $24 per endpoint per year - depending on deployment shape, retention, and integrations.

A self-qualifying range so security teams can decide whether the scoping call makes sense before booking.

Start a scoping call.

Thirty minutes. No slides. We ask what you’re trying to detect, you ask us anything, and we decide together whether Vedric is a fit.

Request early accessTalk to security teamResponse within one business day.