Every Veridenti capability, grouped the way you'll actually use it: protection working inside every browser, governance reporting to your board and your SIEM, administration wired into the identity stack you already run — all on a vault the vendor can't read.
How to read this document
Veridenti is one agent in the browser, one console for the program, and one integration surface for your stack. Each layer is complete on its own; together they close the loop — protection creates the signal, governance proves it, administration keeps it running without tickets.
What every user gets in every browser, with nothing to configure.
What security leadership sees, proves, and streams.
What IT wires up once — then lets the directory drive.
Layer 01 — at the edge
Most credential incidents start with a person on a page. This layer lives exactly there — it repairs itself when sites break, refuses to fill on impostor domains, and gives every vendor relationship its own identity so a leak has nowhere to spread.
When a site changes its login form, Veridenti repairs the fill automatically — fixing the class of breakage, not one site at a time. No tickets, no fallback to typing and reuse.
Credentials fill only on the exact domain they belong to. A look-alike domain gets a warning — never a password. Phishing fails structurally, not just when people are alert.
A unique address for every vendor, generated at sign-up and filled automatically. No shared work address linking four hundred accounts into one target list.
A vendor leaks? Revoke that site's alias in one click. The phishing channel dies, the leaked pair is useless everywhere else, and the rest of the vault never notices.
Leaked-password and breached-domain checks, computed on-device against breach corpora — you get the warning, and no secret or lookup ever phones home.
Weak, reused, and stale credentials are flagged the moment they exist, with a guided fix. The exposure backlog shrinks instead of silently compounding.
In the browser
Nothing to learn, nothing to configure. The right identity appears in the right field on the right site — and when the page changes underneath it, the fill repairs itself before anyone notices there was a problem.
Layer 02 — in the console
The console turns credential hygiene into evidence: one trending risk number for the board, a hash-chained audit trail for the assessors, and a live stream into the SIEM your team already watches — all built on counts and scores, never on secrets.
Reused, weak, breached, MFA-gapped, stale — rolled into one board-reportable index, trending by team and quarter. Computed on-device; the console sees counts, never credentials.
Every admin action lands in a hash-chained log whose integrity anyone can verify independently. No "trust our export" — the chain either checks out or it doesn't.
Audit and risk events stream to Splunk (native HEC) and Datadog natively — and to Microsoft Sentinel or any SIEM via a generic HTTPS collector. Your analysts stay in their console.
Scheduled campaigns walk owners through re-attesting who still needs each shared credential and vault. Access that no one will vouch for expires — with the decision on the record.
Every capability carries three policy verbs, set per group: allow it, require it, or deny it. Your security posture is configuration, not a hope about behavior.
Unusual patterns — bulk access, off-hours export, sudden scope changes — surface as review-ready signals for your team, without surveilling content or reading a single secret.
“Policy you can set, logs you can verify, risk you can trend. Governance isn't a PDF you attach to the audit — it's a property of the system.”
Veridenti design principle № 2Layer 03 — in your stack
Everything an IT team needs to run credential security like infrastructure: identity-driven provisioning, domains that keep shadow accounts from forming, recovery your own officers control, and one seat that covers work, personal, and family — cleanly separated.
SAML/OIDC sign-in and directory-driven provisioning. Included on Enterprise plans (50+ seats); an at-cost add-on for smaller teams.1
Directory groups map to Veridenti roles and vault access automatically. Change the group, and rights follow — no per-user administration.1
Verified company domains route new sign-ups into the org automatically — shadow accounts never form outside your control.
See every device and active session per user, and revoke any of them remotely. A lost laptop is a click, not an incident.
Recovery requires a quorum of officers you designate — for example 3 of 5. Veridenti holds no key and can't be compelled to produce one.
Vault data is region-pinned and fails closed. Global today; EU/US and per-country pinning on Enterprise contract.2
API keys and machine credentials live in governed vaults with owners, rotation reminders, and the same audit trail as human access.
Every seat includes personal and family vaults — zero-knowledge-separate from the org, invisible to admins, and portable if the employee leaves.
Personal use is a security control, not a perk. When work and personal credentials live in one well-run tool, the reuse bridge between them disappears — and so does the most common path from a personal breach to a corporate one.
Feature matrix
Every protection capability is in every business plan — we don't sell safety back by the tier. Enterprise adds the identity plumbing and deep governance a larger program needs.
| Capability | Business | Enterprise (50+ seats) |
|---|---|---|
| 01 · Protection at the edge, in every browser | ||
| Self-healing autofillBroken login forms repaired automatically | ||
| Phishing & look-alike defenseExact-domain fill; impostors get a warning, never a password | ||
| Per-site masked email + one-click containmentUnique alias per vendor; revoke instantly on a leak | ||
| Leaked-password & breached-domain monitoringComputed on-device — no phone-home | ||
| Strength, reuse & staleness detectionFlagged at creation, with a guided fix | ||
| 02 · Governance & Reporting measured and proven in the console | ||
| Human-risk dashboardOne board-reportable index, trending by team | ||
| Tamper-evident, hash-chained auditIntegrity anyone can verify independently | ||
| Feature governance (allow / require / deny)Every capability policy-controlled per group | ||
| SIEM streamingSplunk HEC & Datadog native; Sentinel + any SIEM via HTTPS collector | — | |
| Access recertificationScheduled attestation campaigns for shared access | — | |
| Insider-threat anomaly signalsBehavioral signals without content surveillance | — | |
| 03 · Administration wired into your identity stack | ||
| SSO (SAML / OIDC) + SCIM provisioningDirectory-driven seats, roles, and deprovisioning | At-cost add-on¹ | |
| Group → role mappingDirectory groups drive roles and vault access | With SCIM¹ | |
| Managed & enrollment domainsVerified domains route sign-ups into the org | ||
| Device & session visibility with remote revokeEvery device, every session, one click to end any | ||
| Org recovery (M-of-N officers)Your quorum approves; the vendor holds no key | ||
| Region residency²Region-pinned, fails closed; EU/US & per-country on Enterprise contract | ||
| Service-account secretsMachine credentials in governed, audited vaults | — | |
| Personal & family use per seatIncluded, zero-knowledge-separate, admin-invisible | ||
1 SSO (SAML/OIDC) and SCIM are included on Enterprise plans (50+ seats) and available to smaller teams as an at-cost add-on. Group→role mapping rides on SCIM. 2 Vault data is region-pinned and fails closed. Global today; EU/US and per-country pinning available on Enterprise contract.
Assurance
We'd rather tell you exactly where our compliance program stands than round up. The architecture is the strongest claim we make — and it's the one you can verify yourself.
Readiness program in progress — Type I targeted first, with controls and policies already operating.
Planned — on the certification roadmap following SOC 2.
Available at contracting — counsel-approved terms executed as part of your agreement.
Zero-knowledge vaults and a tamper-evident, hash-chained audit your assessors can check without trusting us.
Next step
A pilot takes a week: connect your identity provider, import from your current manager, and watch the risk baseline draw itself. Every capability on these pages is in the product — not on a roadmap slide.
Start nowveridenti.com — deploy from $3/seat today
Talk to salessales@veridenti.com — pilots, pricing at scale, security review