Veridenti
Feature Overview · Enterprise

The complete platform, on one page. Protect people. Govern risk. Run it at scale.

Every Veridenti capability, grouped the way you'll actually use it: protection working inside every browser, governance reporting to your board and your SIEM, administration wired into the identity stack you already run — all on a vault the vendor can't read.

EXPOSURE STAYS OUTSIDE ZERO-KNOWLEDGE VAULT 01 · PROTECTION Enforced at the edge, in every browser 02 · GOVERNANCE Measured and proven in the console 03 · ADMINISTRATION Wired into your identity stack ONE AGENT · ONE CONSOLE · ONE PLATFORM
20+capabilities across three layers — every one on these pages
0passwords Veridenti can read — ever
1clickto contain a vendor breach
3policy verbs — allow, require, deny — on every capability

How to read this document

Three layers, one system.

Veridenti is one agent in the browser, one console for the program, and one integration surface for your stack. Each layer is complete on its own; together they close the loop — protection creates the signal, governance proves it, administration keeps it running without tickets.

Layer 01

Protection

What every user gets in every browser, with nothing to configure.

  • Self-healing autofill
  • Phishing & look-alike defense
  • Per-site masked email
  • One-click breach containment
  • Leak & breached-domain monitoring
  • Strength & reuse detection
Layer 02

Governance & Reporting

What security leadership sees, proves, and streams.

  • Human-risk dashboard
  • Tamper-evident audit
  • SIEM streaming
  • Access recertification
  • Feature governance
  • Insider-threat anomaly signals
Layer 03

Administration

What IT wires up once — then lets the directory drive.

  • SSO + SCIM · group→role mapping
  • Managed & enrollment domains
  • Device & session visibility
  • Org recovery (M-of-N)
  • Region residency · service accounts
  • Personal & family use per seat

Layer 01 — at the edge

01

Protection: security that works because it keeps working.

Most credential incidents start with a person on a page. This layer lives exactly there — it repairs itself when sites break, refuses to fill on impostor domains, and gives every vendor relationship its own identity so a leak has nowhere to spread.

Self-healing autofill

When a site changes its login form, Veridenti repairs the fill automatically — fixing the class of breakage, not one site at a time. No tickets, no fallback to typing and reuse.

Phishing & look-alike defense

Credentials fill only on the exact domain they belong to. A look-alike domain gets a warning — never a password. Phishing fails structurally, not just when people are alert.

Per-site masked email

A unique address for every vendor, generated at sign-up and filled automatically. No shared work address linking four hundred accounts into one target list.

One-click breach containment

A vendor leaks? Revoke that site's alias in one click. The phishing channel dies, the leaked pair is useless everywhere else, and the rest of the vault never notices.

Leak & breached-domain monitoring

Leaked-password and breached-domain checks, computed on-device against breach corpora — you get the warning, and no secret or lookup ever phones home.

Strength & reuse detection

Weak, reused, and stale credentials are flagged the moment they exist, with a guided fix. The exposure backlog shrinks instead of silently compounding.

ANATOMY OF A PROTECTED SIGN-IN 1 · DOMAIN CHECK Exact-match domain verification Is this really the site? 2 · FORM CHECK Markup changed? The fill self-heals No broken autofill, ever 3 · IDENTITY Masked alias + strong unique password Unique to this vendor 4 · AFTERWARD Leak & breach checks continue on-device No phone-home, ever acrne-payroll.com LOOK-ALIKE — NOTHING FILLS, USER WARNED Verified fill, contained by design Blast radius if leaked: one alias EVERY SIGN-IN, EVERY BROWSER, ZERO USER EFFORT

In the browser

What your people actually see.

Nothing to learn, nothing to configure. The right identity appears in the right field on the right site — and when the page changes underneath it, the fill repairs itself before anyone notices there was a problem.

portal.vendor-payroll.com ✓ VERIFIED MATCH Sign in EMAIL payroll.m4t7@vrd.email MASKED · UNIQUE TO THIS SITE PASSWORD STRONG · NOT REUSED ✓ Form changed — fill self-healed ✓ Repaired automatically · no action needed 0 reused across this user's 214 logins
  • Adoption that sticks. The fill works on day one and keeps working when sites change — so people never fall back to typing and reusing.
  • Identity per vendor, automatically. Masked alias and unique password are generated and filled without the user managing anything.
  • An explicit user action always wins. Every automated choice is a recommendation the user can override in place. It's their data.

Layer 02 — in the console

02

Governance: risk you can measure, logs you can verify.

The console turns credential hygiene into evidence: one trending risk number for the board, a hash-chained audit trail for the assessors, and a live stream into the SIEM your team already watches — all built on counts and scores, never on secrets.

Human-risk dashboard

Reused, weak, breached, MFA-gapped, stale — rolled into one board-reportable index, trending by team and quarter. Computed on-device; the console sees counts, never credentials.

Tamper-evident audit

Every admin action lands in a hash-chained log whose integrity anyone can verify independently. No "trust our export" — the chain either checks out or it doesn't.

SIEM streaming

Audit and risk events stream to Splunk (native HEC) and Datadog natively — and to Microsoft Sentinel or any SIEM via a generic HTTPS collector. Your analysts stay in their console.

Access recertification

Scheduled campaigns walk owners through re-attesting who still needs each shared credential and vault. Access that no one will vouch for expires — with the decision on the record.

Feature governance

Every capability carries three policy verbs, set per group: allow it, require it, or deny it. Your security posture is configuration, not a hope about behavior.

AllowRequireDeny

Insider-threat anomaly signals

Unusual patterns — bulk access, off-hours export, sudden scope changes — surface as review-ready signals for your team, without surveilling content or reading a single secret.

HASH-CHAINED AUDIT LOG e1021a3f2… e10227d0c… e1023b6e4… e1024f19a… each entry seals the one before it CHAIN VERIFIED ✓ · UNEDITED STREAMED WHERE YOUR TEAM ALREADY LOOKS Veridenti console Splunk NATIVE · HTTP EVENT COLLECTOR Datadog NATIVE Microsoft Sentinel + any SIEM GENERIC HTTPS COLLECTOR SEALED AT THE SOURCE · VERIFIABLE BY ANYONE · STREAMED IN REAL TIME

“Policy you can set, logs you can verify, risk you can trend. Governance isn't a PDF you attach to the audit — it's a property of the system.”

Veridenti design principle № 2

Layer 03 — in your stack

03

Administration: wire it up once, let the directory drive.

Everything an IT team needs to run credential security like infrastructure: identity-driven provisioning, domains that keep shadow accounts from forming, recovery your own officers control, and one seat that covers work, personal, and family — cleanly separated.

SSO + SCIM

SAML/OIDC sign-in and directory-driven provisioning. Included on Enterprise plans (50+ seats); an at-cost add-on for smaller teams.1

Group → role mapping

Directory groups map to Veridenti roles and vault access automatically. Change the group, and rights follow — no per-user administration.1

Managed & enrollment domains

Verified company domains route new sign-ups into the org automatically — shadow accounts never form outside your control.

Device & session visibility

See every device and active session per user, and revoke any of them remotely. A lost laptop is a click, not an incident.

Org recovery (M-of-N)

Recovery requires a quorum of officers you designate — for example 3 of 5. Veridenti holds no key and can't be compelled to produce one.

Region residency

Vault data is region-pinned and fails closed. Global today; EU/US and per-country pinning on Enterprise contract.2

Service-account secrets

API keys and machine credentials live in governed vaults with owners, rotation reminders, and the same audit trail as human access.

Personal & family use per seat

Every seat includes personal and family vaults — zero-knowledge-separate from the org, invisible to admins, and portable if the employee leaves.

SEAT LIFECYCLE, DRIVEN BY YOUR DIRECTORY JOINER Okta · Entra · any SAML/OIDC SCIM Seat provisioned on day one vaults & role assigned by group MOVER Group changes in the directory Roles & vault access remap no per-user admin work LEAVER User deactivated in the directory Deprovisioned · sessions revoked ✓ org access ends everywhere, at once YOUR DIRECTORY IS THE SOURCE OF TRUTH — SEATS SIMPLY FOLLOW IT

Personal use is a security control, not a perk. When work and personal credentials live in one well-run tool, the reuse bridge between them disappears — and so does the most common path from a personal breach to a corporate one.

Feature matrix

What ships where.

Every protection capability is in every business plan — we don't sell safety back by the tier. Enterprise adds the identity plumbing and deep governance a larger program needs.

Capability Business Enterprise (50+ seats)
01 · Protection at the edge, in every browser
Self-healing autofillBroken login forms repaired automatically
Phishing & look-alike defenseExact-domain fill; impostors get a warning, never a password
Per-site masked email + one-click containmentUnique alias per vendor; revoke instantly on a leak
Leaked-password & breached-domain monitoringComputed on-device — no phone-home
Strength, reuse & staleness detectionFlagged at creation, with a guided fix
02 · Governance & Reporting measured and proven in the console
Human-risk dashboardOne board-reportable index, trending by team
Tamper-evident, hash-chained auditIntegrity anyone can verify independently
Feature governance (allow / require / deny)Every capability policy-controlled per group
SIEM streamingSplunk HEC & Datadog native; Sentinel + any SIEM via HTTPS collector
Access recertificationScheduled attestation campaigns for shared access
Insider-threat anomaly signalsBehavioral signals without content surveillance
03 · Administration wired into your identity stack
SSO (SAML / OIDC) + SCIM provisioningDirectory-driven seats, roles, and deprovisioning At-cost add-on¹
Group → role mappingDirectory groups drive roles and vault access With SCIM¹
Managed & enrollment domainsVerified domains route sign-ups into the org
Device & session visibility with remote revokeEvery device, every session, one click to end any
Org recovery (M-of-N officers)Your quorum approves; the vendor holds no key
Region residency²Region-pinned, fails closed; EU/US & per-country on Enterprise contract
Service-account secretsMachine credentials in governed, audited vaults
Personal & family use per seatIncluded, zero-knowledge-separate, admin-invisible
Included Add-on Available at cost Not included

1  SSO (SAML/OIDC) and SCIM are included on Enterprise plans (50+ seats) and available to smaller teams as an at-cost add-on. Group→role mapping rides on SCIM.   2  Vault data is region-pinned and fails closed. Global today; EU/US and per-country pinning available on Enterprise contract.

Assurance

Straight answers for your security review.

We'd rather tell you exactly where our compliance program stands than round up. The architecture is the strongest claim we make — and it's the one you can verify yourself.

SOC 2

Readiness program in progress — Type I targeted first, with controls and policies already operating.

ISO 27001

Planned — on the certification roadmap following SOC 2.

DPA & BAA

Available at contracting — counsel-approved terms executed as part of your agreement.

Verifiable by design

Zero-knowledge vaults and a tamper-evident, hash-chained audit your assessors can check without trusting us.

Next step

See all three layers on your own tenant.

A pilot takes a week: connect your identity provider, import from your current manager, and watch the risk baseline draw itself. Every capability on these pages is in the product — not on a roadmap slide.

$3 per user / month to start

Start nowveridenti.com — deploy from $3/seat today

Talk to salessales@veridenti.com — pilots, pricing at scale, security review