Persistence + staged collection sequence
endpoint-042 · corporate device
Your perimeter is guarded. The inside is trusted - until it isn't. Vedric learns each user's baseline and flags the behavioral drift that EDR, SIEM, and UEBA miss.
endpoint-042 · corporate device
PRIVACY ENFORCED IN CODE
No keystrokes, screenshots, or file payloads. A bounded, redacted PowerShell script preview is the documented exception.
Every agent message is cryptographically signed - tamper-evident from endpoint to cloud.
Three audit surfaces reject edits and deletes by the application database role; independent exports cover infrastructure-admin threat models.
Tenant-scoped queries and row-level database controls, exercised by build-time isolation tests.
Now selecting a small group of design partners. If insider risk is on your roadmap this year, we should talk.
This is a composite of behavioral shapes Vedric reads in the run-up to a departure. This is one anomaly shape among several. Identifying details removed. Specific thresholds stay inside the product.
Vedric's baseline engine doesn't know the difference between malicious, accidental, and automated. It knows the difference between normal and not. That's what makes it useful across the three shapes most incidents actually take.
A trusted user runs an unusual bulk-copy command and host-level outbound bytes rise sharply. No malicious intent is required for that metadata to justify review; Vedric does not claim which files or destination caused the volume.
A legitimate background task starts with a new command shape while the endpoint's new-destination count and frequency rise. Vedric correlates the process evidence with the endpoint baseline; it does not attribute host network bytes to that process without proof.
Valid credentials, normal login. But once past the door, the behavior doesn't match the legitimate user - different access pattern, different timing, different scope. Vedric compares against the user's own baseline, so a compromised account looks nothing like its owner.
"Show me how you would have seen it if a resigning employee had been preparing to leave with material for two weeks."
Most security programs cannot answer that question. Their tools are built around external attackers, known-bad indicators, or aggregated log scoring. Insider rehearsal falls in the gap between them. Vedric is built for the gap.
Watching people prepare to betray you doesn't require reading their email. It requires watching behavior. Vedric is built around that distinction, and the agent enforces it in its own source code.
Get ahead of the question your auditor, your board, and your CEO will eventually ask. Thirty-minute scoping call. No slides.