Who this policy covers
This Privacy Policy explains how Vedric ("Vedric," "we," "us") collects, uses, discloses, and protects personal data. It applies to three audiences:
- Website visitors - anyone browsing vedric.io or related public properties.
- Customer personnel - administrators, analysts, and other users at organizations that have purchased our Services.
- End-users of monitored endpoints - employees, contractors, and other personnel of our Customers whose workstation activity is observed by the Vedric agent. Important: Vedric does not have a direct relationship with these individuals. See Section 4.
Data we collect from website visitors
When you visit vedric.io, we collect basic web analytics: IP address, browser type, pages requested, referring URL, and approximate geographic region. We use this to operate the website and understand which content is useful. We do not use third-party advertising trackers, cross-site identifiers, or sell visitor data.
If you contact us through the demo form or by email, we collect the information you provide (typically name, work email, company, role, and message contents) to respond to your inquiry.
Data we collect from customer accounts
When a customer organization creates an account, administrators provide names, work email addresses, and role designations for users who will access the Vedric platform. We use this information to authenticate users, deliver service notifications, and provide support.
We collect operational telemetry from the Vedric platform (logins, audit events, support tickets) to maintain the service, investigate incidents, prevent abuse, and improve product quality.
Endpoint telemetry and the controller / processor relationship
The Vedric agent runs on endpoints owned or managed by our Customers and collects behavioral metadata about activity on those endpoints. For this telemetry, Vedric acts as a "data processor" (or equivalent role under applicable law). The Customer is the "data controller." This means:
- The Customer determines the purposes and means of processing.
- The Customer is responsible for establishing the lawful basis for monitoring (typically employer's legitimate interest in security, or consent), and for providing notice to monitored individuals as required by law.
- Vedric processes endpoint telemetry only as instructed by the Customer through configuration of the Services and as necessary to deliver the Services.
- Requests from monitored individuals (access, correction, deletion, portability, objection) should be addressed to the Customer organization, who controls the data. Vedric will assist Customers in responding to such requests as required by Article 28 GDPR or equivalent law.
For Customers subject to GDPR or similar regulations, we offer a Data Processing Addendum (DPA) governing this relationship. Request a copy at support@vedric.io.
What endpoint telemetry actually contains
The agent captures behavioral metadata. There is one content-bearing exception, and it is set out in full below.
What is collected
- Process and command-line metadata.
- Authentication and privilege-change events.
- Host-level network connection/unique/new-destination counts and byte-rate deltas, plus bounded DNS query metadata when configured.
- File-system activity metadata (extension, size, location - never contents).
- Removable-media activity.
- Persistence-mechanism inventory.
- A PowerShell script-block preview, truncated to 2 KB and passed through best-effort secret redaction, where host logging is enabled.
- Kernel-level process metadata where available.
What the agent does not collect
- File contents.
- Keystrokes.
- Screenshots.
- Browser history or page content.
- Email or chat message bodies.
- Clipboard data.
- Microphone or camera input.
- Location-services data.
These code paths are not present in the agent. End-user identifiers from the endpoint are anonymized at the source through a one-way cryptographic transformation before transmission.
PowerShell script text can contain sensitive business or personal data even after recognizable credentials are redacted. By default, Vedric only observes Script Block Logging already enabled by the Customer or Group Policy and does not change the machine-wide HKLM policy. A Customer can explicitly opt into agent-managed logging with VEDRIC_MANAGE_POWERSHELL_SCRIPT_BLOCK_LOGGING=true; the agent durably records and audits the prior value before changing it, then verifies restoration on opt-out or orderly shutdown. Customers are responsible for notice, lawful basis, and works-council consultation where applicable.
How DNS observation works
DNS query metadata - the domain strings your endpoints resolve - is retained as observed within your tenant. We keep the domain string itself rather than a hash because behavioral detection compares domains against the endpoint's own history and against published threat-indicator feeds; both require the original string to be meaningful.
We do not record the IP addresses returned by DNS responses beyond aggregate counts, the data subsequently transferred to or from those domains, the bodies of any web requests, or any client-side DNS cache contents beyond the queries actually made by monitored processes. Domain telemetry is isolated to the customer's tenant and is never shared cross-customer or used to train cross-customer models without express consent.
The same limits govern AI-assisted triage. Because Vedric never collects file contents, keystrokes, screen data, or message bodies, there is none to send: what reaches our AI provider is the pseudonymized, secret-scrubbed metadata described in Section 8.
How we use personal data
- Provide, maintain, secure, and improve the Services.
- Generate behavioral baselines and security alerts for the Customer organization.
- Generate AI-assisted triage summaries and recommended verdicts for alerts, where the Customer organization has that feature enabled (see Section 8).
- Authenticate users and enforce access controls.
- Communicate about accounts, service changes, security notices, and support.
- Comply with legal obligations and respond to lawful government requests.
- Investigate suspected violations of our terms or applicable law.
- Defend Vedric's legal rights, property, and the safety of others.
We do not sell, rent, or share personal data with third parties for their marketing purposes. We do not use endpoint telemetry to train cross-customer models without the Customer's express consent.
Lawful bases for processing (GDPR / UK GDPR)
Where Vedric is the controller of personal data (e.g., for visitor analytics, customer account administration, payment processing), our lawful bases include:
- Performance of a contract - to deliver the Services to our Customers.
- Legitimate interests - to operate, secure, and improve our Services and protect against abuse.
- Legal obligation - to comply with tax, accounting, audit, and other legal requirements.
- Consent - where applicable, such as marketing communications you can opt out of at any time.
Where Vedric is the processor (endpoint telemetry from a Customer's environment), the lawful basis is established by the Customer as controller.
Data sharing and subprocessors
We share personal data only as follows:
- With our AI provider - when AI-assisted triage is enabled for your organization, alert evidence is sent to OpenAI to summarize what happened and suggest a verdict. Evidence can include the documented bounded PowerShell preview. Before anything leaves Vedric it passes through an additional scrubbing layer that pseudonymizes hostnames and usernames, collapses file paths, truncates long values, and redacts recognizable secrets such as private keys, tokens, and credentials passed on a command line. We do not send file payloads, keystrokes, screen captures, or message bodies because Vedric does not collect them. An organization administrator can disable AI-assisted triage at any time under Settings, Privacy & Data Sharing; when it is disabled no alert data is sent to any AI provider and alerts are scored solely by Vedric's own detection engine. Changes to that setting are recorded in your audit log.
- With subprocessors who help us operate the Services. We require subprocessors to handle data with at least the same protections required by this Policy. Our current list is published at vedric.io/subprocessors, and we provide at least thirty (30) days advance notice before adding a new subprocessor that processes Customer Data, except where prevented by law.
- With our Customers - endpoint telemetry collected from a Customer's environment is shown to that Customer only.
- To comply with law - in response to a valid legal process or to protect rights, property, or safety.
- In connection with a corporate transaction - merger, acquisition, or sale of assets, with notice as required by law.
International data transfers
Vedric is operated from the United States and our infrastructure may store and process data in multiple jurisdictions. For Customers in the European Economic Area, United Kingdom, or Switzerland, we rely on Standard Contractual Clauses (or equivalent legal mechanisms in force from time to time) to provide an adequate level of protection for personal data transferred internationally.
Data retention
We retain personal data only as long as necessary for the purposes outlined in this Policy, or as required by law:
- Visitor analytics: aggregated after a short window; raw logs typically retained for less than ninety (90) days.
- Customer account information: for the duration of the subscription plus a reasonable period thereafter for legal and operational purposes.
- Endpoint telemetry (active tier): retained per the Customer's configured retention windows for live detection and the analyst surface. Default windows are configurable by the Customer; the Customer instructs Vedric on retention through Service settings.
- Forensic cold-archive tier: beyond the tenant's active database-retention window, expired telemetry, deviations, and training examples are moved to a compressed cold archive before database deletion. The archive uses the platform-configured retention window (365 days by default), which is disclosed in the tenant's privacy receipt. It contains the same bounded telemetry as the active tier, including any documented PowerShell preview, but not file payloads, keystrokes, screens, or message bodies. The Customer may request earlier deletion of archived telemetry through written notice.
- Audit logs and forensic records: retained as required by the Customer's compliance obligations and our legitimate operational interests; the Customer may request earlier deletion through written notice.
- Backups: routine database backup objects are currently configured for lifecycle deletion 90 days after creation. Azure lifecycle evaluation is asynchronous; after deletion, Azure Blob soft deletion retains a restricted recovery copy for 30 days. These are configured retention windows, not an exact deletion deadline, and a legal hold may extend retention. Vedric does not represent an independent cold-archive backup as active until its restore controls have passed a recovery drill.
- Tenant-deletion safety records: tenant deletion is not reported complete until database, cold-archive, and shadow-log cleanup has been reconciled. During reconciliation, a restricted retry marker can temporarily contain the tenant identifier. After cleanup, Vedric may retain only a SHA-256 digest of that identifier and a completion timestamp as a suppression record against delayed processing; it contains no endpoint telemetry or raw tenant identifier.
Security
We implement reasonable and appropriate technical and organizational measures designed to protect personal data, including encryption of data in transit and at rest, multi-factor authentication for administrative access, role-based access controls, payload integrity verification on agent communications, append-only audit trails for sensitive actions, and regular review of access permissions. Third-party security assessments are scheduled.
No system is perfectly secure. While we work to protect personal data, we cannot guarantee absolute security against all threats, including those involving sophisticated or state-sponsored adversaries.
Security incident notification
If Vedric becomes aware of a security incident affecting personal data we process, we will notify affected Customers without undue delay and, in any event, within seventy-two (72) hours of confirming the incident, in accordance with applicable law. Notification will include the nature of the incident, the categories and approximate volume of data affected, the likely consequences, and the measures taken or proposed to address it.
Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, port, or restrict the processing of personal data we hold about you, and to object to certain processing activities. You may also have the right to lodge a complaint with a supervisory authority.
If Vedric is the controller of your data, contact us at support@vedric.io. If Vedric is processing your data on behalf of a Customer (such as endpoint telemetry from your employer's environment), please direct your request to the Customer organization in the first instance - they control the data and we will support them in responding.
California residents (CCPA / CPRA)
The California Consumer Privacy Act provides specific rights including the right to know what personal information is collected, to access and delete that information, to opt out of "sale" or "sharing" (we do not sell or share personal information as defined under CCPA), and to non-discrimination for exercising your rights. Submit verifiable consumer requests to support@vedric.io.
Children's privacy
Our Services are designed for use by organizations and their personnel, not by children. We do not knowingly collect personal information from individuals under sixteen (16) (or the age of digital consent in your jurisdiction). If we learn we have collected such information, we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by updating the "Last updated" date and, where appropriate, by notice on our website or to administrators of active Customer accounts. Your continued use of the Services after changes take effect constitutes acceptance of the updated Policy.
Contact
Privacy questions, data-subject requests, and notices under this Policy can be directed to the addresses below.
- PRIVACY + LEGAL
- support@vedric.io
- SUPPORT
- support@vedric.io
- SALES
- support@vedric.io
- WEBSITE
- vedric.io
- DPA REQUESTS
- Email support@vedric.io with subject "DPA Request"
For complaints to a supervisory authority, EEA / UK / Swiss residents may contact their local data protection authority directly. A current list is maintained by the European Data Protection Board and, for the UK, by the Information Commissioner's Office.
