BEHAVIORAL INSIDER-RISK DETECTION

See insider risk before it becomes damage.

Your perimeter is guarded. The inside is trusted - until it isn't. Vedric learns each user's baseline and flags the behavioral drift that EDR, SIEM, and UEBA miss.

Content-minimizing by design Windows today
VEDRIC · LIVE DETECTION MONITORING
2026-04-22 18:42 UTC
STORY-7F3A
HIGH

Persistence + staged collection sequence

endpoint-042 · corporate device

source: endpoint telemetry·pattern: off-baseline sequence·correlated: 14 events
PersistenceCollection
14-DAY REHEARSALpre-departure window
VEDRIC
11
EDR/SIEM
0

PRIVACY ENFORCED IN CODE

Content-minimizing

No keystrokes, screenshots, or file payloads. A bounded, redacted PowerShell script preview is the documented exception.

Signed wire

Every agent message is cryptographically signed - tamper-evident from endpoint to cloud.

Append-only audit

Three audit surfaces reject edits and deletes by the application database role; independent exports cover infrastructure-admin threat models.

Tenant-isolated

Tenant-scoped queries and row-level database controls, exercised by build-time isolation tests.

Now selecting a small group of design partners. If insider risk is on your roadmap this year, we should talk.

ONE SCENARIO · THE REHEARSAL

Fourteen days of signal. Eleven chances to act.

This is a composite of behavioral shapes Vedric reads in the run-up to a departure. This is one anomaly shape among several. Identifying details removed. Specific thresholds stay inside the product.

  1. DAY 01
    Normal. Shipping code on the same projects they've owned for two years.
    baseline · no signal
    -
  2. DAY 03
    First off-baseline activity shape. Query pattern outside their six-month norm.
    deviation logged · not yet alerting
    VEDRIC
  3. DAY 05
    A first-time administrative command targets a system outside the recent project pattern.
    command-scope drift · correlated with day 03
    VEDRIC
  4. DAY 06
    Normal working-hours activity. No further drift.
    watching
    -
  5. DAY 08
    Off-hours process and command activity increases in a window the user never worked in before.
    temporal deviation
    VEDRIC
  6. DAY 09
    Storyline correlated. Three deviations, same user, same endpoint, six days.
    storyline materialized
    VEDRIC
  7. DAY 10
    Normal. User takes a half-day off.
    watching
    -
  8. DAY 11
    Privileged query not run in the last six months. Legitimate access - but not legitimate timing.
    privilege drift
    VEDRIC
  9. DAY 12
    Another command targets a repository service outside the current team pattern.
    command-scope drift, second instance
    VEDRIC
  10. DAY 13
    Egress volume above their personal baseline, during hours they don't normally work.
    exfiltration-shaped pattern
    VEDRIC
  11. DAY 14
    Employee submits resignation notice. HR is told. Their laptop is on the forfeit list.
    (Vedric had eleven days of warning)
    -
VEDRIC SAW
11 / 14
days of correlated behavioral drift before the resignation meeting was on anyone's calendar.
YOUR CURRENT STACK SAW
0 / 14
days. SIEM aggregates events, EDR watches processes, UEBA scores logins. None of them correlate endpoint behavior over time against the user's own baseline.
BEYOND INTENT

A deviation is a deviation - regardless of who caused it.

Vedric's baseline engine doesn't know the difference between malicious, accidental, and automated. It knows the difference between normal and not. That's what makes it useful across the three shapes most incidents actually take.

01 /ACCIDENT

The honest mistake

A trusted user runs an unusual bulk-copy command and host-level outbound bytes rise sharply. No malicious intent is required for that metadata to justify review; Vedric does not claim which files or destination caused the volume.

02 /AUTOMATION

The drifting process

A legitimate background task starts with a new command shape while the endpoint's new-destination count and frequency rise. Vedric correlates the process evidence with the endpoint baseline; it does not attribute host network bytes to that process without proof.

03 /COMPROMISE

The borrowed account

Valid credentials, normal login. But once past the door, the behavior doesn't match the legitimate user - different access pattern, different timing, different scope. Vedric compares against the user's own baseline, so a compromised account looks nothing like its owner.

THE GAP

The question your auditor is already asking.

"Show me how you would have seen it if a resigning employee had been preparing to leave with material for two weeks."

Most security programs cannot answer that question. Their tools are built around external attackers, known-bad indicators, or aggregated log scoring. Insider rehearsal falls in the gap between them. Vedric is built for the gap.

WHAT WE SEE - AND REFUSE TO SEE

What Vedric sees.
What Vedric refuses to see.

Watching people prepare to betray you doesn't require reading their email. It requires watching behavior. Vedric is built around that distinction, and the agent enforces it in its own source code.

PRIVACY RECEIPT
issued at agent install · re-verified per collector pass
COLLECTED
  • Process + parent-process metadata
  • Command-line activity
  • Authentication events
  • Network destinations (IPs, domains)
  • File activity metadata (counts, types)
  • Endpoint health + heartbeat
REFUSED
  • File contents
  • Keystrokes
  • Screen contents / screenshots
  • Email and chat message bodies
  • Document bodies
  • Browser content / page source
Enforced in code, not policy.
agent-side · cannot be extended remotely

Don’t be the CISO who finds out in court.

Get ahead of the question your auditor, your board, and your CEO will eventually ask. Thirty-minute scoping call. No slides.

Join the waitlistTalk to security teamResponse within one business day.