TRUST & SECURITY

Privacy is enforced at the collector.

Code paths for capturing file content, keystrokes, or screenshots do not exist in the agent. A tenant admin can export a current privacy receipt that discloses collection categories, the bounded PowerShell script-preview exception, retention, and sharing settings; it is tenant-level disclosure, not a per-alert evidence signature.

01Content-minimizing
02Tenant-isolated
03Signed wire
04No message content
01

WHAT WE REFUSE TO SEE

A refusal list, enforced in the agent itself.

01

Keystrokes

Behavioural shape, not typed content, is what an insider’s pattern shows. Storing keystrokes is surveillance theater that creates legal liability without adding signal.

02

Screen content

A screenshot pipeline is a continuous capture of everything an employee reads and writes. That category of data has no legitimate home in an insider-risk product.

03

Document contents

The agent reports bounded sensitive-extension inventory counts and removable-media write metadata, never file payloads or a per-file read history. The content-scanner capability does not exist in the agent.

04

Email and chat bodies

Communication content belongs to the people communicating. Insider-risk signal lives in patterns of access and movement, not in the messages themselves.

05

Browsing history

Page-level browser history mixes work and personal activity in ways no employer should ingest by default. Network-layer signal is sufficient and proportional.

06

Microphone and camera

Audio and video capture have no place in a behavioural-risk platform. There is no code path in the agent that activates either device.

The capabilities above are not toggles. There is no configuration, update, or operator role that turns them on.

02

WHAT WE OBSERVE

Deliberately minimized, with one documented script-text exception.

The categories below describe what an insider-risk platform needs to see at all. Specifics live in the per-tenant privacy receipt.

01 /

Behavioural signals across the host layer

Primarily characteristics of activity on the device: process, authentication, file-system, and host-state metadata.

02 /

Identity-anomalous patterns across login and access

When, how often, and through which observed process/command shapes privileged activity occurs, relative to available personal and peer history.

03 /

Network-level destination diversity

Host-level connection, unique/new-destination counts and byte-rate deltas, plus bounded DNS metadata when configured. No packet or page content.

04 /

Persistence and integrity changes

Changes that affect whether the host will behave the same way tomorrow as it did yesterday. State, not content.

05 /

Bounded PowerShell script evidence

When host Script Block Logging is enabled, up to 2 KB of executed script text is retained after best-effort secret redaction. This is the explicit content-bearing exception.

PRIVACY RECEIPT

A receipt of exactly what your tenant's data shows - exportable for audit.

Every tenant admin can export a privacy receipt covering the trailing 30 days. It shows the categories of data Vedric processed (with counts), the categories Vedric explicitly did not collect, effective telemetry/deviation and cold-archive settings, current AI-egress and aggregate-baseline choices, and online versus enrolled agents. Its HMAC is a server integrity checksum with a key ID, not an independently customer-verifiable signature; an auditor can compare the receipt with separately exported audit and database records.

SECURITY POSTURE

What an evaluation team will ask - answered up front.

Encryption

  • TLS-protected traffic in transit
  • AES-based encryption for at-rest secrets
  • OS-level credential vault on the endpoint
  • Asymmetric signing for browser session tokens

Authentication

  • Email + password + TOTP (mandatory for operator console)
  • SAML 2.0 SSO with per-tenant IdP configuration
  • JIT user provisioning and group → role mapping
  • Force-signout via SAML SLO and admin control

Tenant isolation

  • Tenant scoping enforced at the data access layer
  • Static and runtime tests exercise tenant-scoped route and query paths
  • Customer content stays tenant-scoped; thresholded global fallback uses derived aggregate statistics only
  • Postgres row-level security as a second, database-enforced barrier beneath the application layer

Audit trails

  • Three independent append-only logs
  • Database-level enforcement against UPDATE / DELETE on audit tables
  • Tenant-visible audit log + operator audit + retention-governed forensic trail
  • Covered privileged actions stamped with actor, time, and reason

Agent integrity

  • Every update signed with an offline Ed25519 key and bound to its version
  • Installer refuses any binary that fails signature verification
  • Auto-update verifies signature before swap; rollback on failure
  • Only the public verification key is compiled into shipped agents

Operational

  • Live system status at status.vedric.io
  • Tenant-configurable database retention for telemetry and deviations; platform cold-archive setting disclosed per receipt
  • Archive-before-delete cleanup fails safe when an archive write fails
  • Backup and restore posture must be verified for each production deployment
  • Production change-control with full audit history

PROCUREMENT

Procurement-ready documentation.

Standard artifacts security teams need before an evaluation. Available on request under NDA.

Security review package
Current control descriptions and known deployment requirements are available for evaluation. This page does not claim a completed independent penetration test or certification.
Request artifactsReply within one business day.