Code paths for capturing file content, keystrokes, or screenshots do not exist in the agent. A tenant admin can export a current privacy receipt that discloses collection categories, the bounded PowerShell script-preview exception, retention, and sharing settings; it is tenant-level disclosure, not a per-alert evidence signature.
WHAT WE REFUSE TO SEE
Behavioural shape, not typed content, is what an insider’s pattern shows. Storing keystrokes is surveillance theater that creates legal liability without adding signal.
A screenshot pipeline is a continuous capture of everything an employee reads and writes. That category of data has no legitimate home in an insider-risk product.
The agent reports bounded sensitive-extension inventory counts and removable-media write metadata, never file payloads or a per-file read history. The content-scanner capability does not exist in the agent.
Communication content belongs to the people communicating. Insider-risk signal lives in patterns of access and movement, not in the messages themselves.
Page-level browser history mixes work and personal activity in ways no employer should ingest by default. Network-layer signal is sufficient and proportional.
Audio and video capture have no place in a behavioural-risk platform. There is no code path in the agent that activates either device.
The capabilities above are not toggles. There is no configuration, update, or operator role that turns them on.
WHAT WE OBSERVE
The categories below describe what an insider-risk platform needs to see at all. Specifics live in the per-tenant privacy receipt.
Primarily characteristics of activity on the device: process, authentication, file-system, and host-state metadata.
When, how often, and through which observed process/command shapes privileged activity occurs, relative to available personal and peer history.
Host-level connection, unique/new-destination counts and byte-rate deltas, plus bounded DNS metadata when configured. No packet or page content.
Changes that affect whether the host will behave the same way tomorrow as it did yesterday. State, not content.
When host Script Block Logging is enabled, up to 2 KB of executed script text is retained after best-effort secret redaction. This is the explicit content-bearing exception.
Every tenant admin can export a privacy receipt covering the trailing 30 days. It shows the categories of data Vedric processed (with counts), the categories Vedric explicitly did not collect, effective telemetry/deviation and cold-archive settings, current AI-egress and aggregate-baseline choices, and online versus enrolled agents. Its HMAC is a server integrity checksum with a key ID, not an independently customer-verifiable signature; an auditor can compare the receipt with separately exported audit and database records.
PROCUREMENT
Standard artifacts security teams need before an evaluation. Available on request under NDA.