Code paths for capturing file content, keystrokes, or screenshots do not exist in the agent. Every alert ships with a verifiable receipt of what data was used to produce it.
WHAT WE REFUSE TO SEE
Behavioural shape, not typed content, is what an insider’s pattern shows. Storing keystrokes is surveillance theater that creates legal liability without adding signal.
A screenshot pipeline is a continuous capture of everything an employee reads and writes. That category of data has no legitimate home in an insider-risk product.
Files are observed by their shape and movement, never by what is inside them. The product cannot regress into a content scanner because the capability does not exist in the agent.
Communication content belongs to the people communicating. Insider-risk signal lives in patterns of access and movement, not in the messages themselves.
Page-level browser history mixes work and personal activity in ways no employer should ingest by default. Network-layer signal is sufficient and proportional.
Audio and video capture have no place in a behavioural-risk platform. There is no code path in the agent that activates either device.
The capabilities above are not toggles. There is no configuration, update, or operator role that turns them on.
WHAT WE OBSERVE
The categories below describe what an insider-risk platform needs to see at all. Specifics live in the per-tenant privacy receipt, not in marketing copy.
Characteristics of activity on the device, categorically, not content. Shape and movement, not what is inside.
Where, when, and how privileged actions occur, relative to a user’s own history and the history of their peers.
The diversity and timing of outbound destinations a host reaches. Destination categories, not page content.
Changes that affect whether the host will behave the same way tomorrow as it did yesterday. State, not content.
Every tenant admin can export a privacy receipt covering the trailing 30 days. It shows the categories of data Vedric processed (with counts), the categories Vedric explicitly did not collect, retention windows, and the audit-trail entries backing each. The export is sourced from append-only logs, so an auditor can cross-check it against the live database.
PROCUREMENT
Standard artifacts security teams need before an evaluation. Available on request under NDA.