Veridenti draws the work/personal line at the browser profile — so a governed profile provably holds only company data, and your employees keep a private vault you can never read, subpoena, or wipe.
Most tools try to keep an employee's personal life and the company's credentials apart inside one vault, and manage the mixing. Veridenti removes the mixing entirely by drawing the boundary at the profile.
One org-governed vault, an Org Recovery Key, and every capture routed to work. The personal vault is disabled by default — there is no personal data on the profile to leak, subpoena, or wipe.
On a separate profile or device, with no Org Recovery Key. Org-blind, portable, and bundled with the seat. The organization holds no key to it — ever.
A work profile beside a personal one on the same machine. A work laptop is simply a work profile. No second device required, no personal data on the governed side.
The same trust boundary 1Password draws at the app account, we draw at the profile. That one move removes the entire class of work/personal mixing risk instead of trying to manage it.
Personal use is off on the governed profile — the strictest, cleanest audit, DLP, and legal-hold scope, and the posture the EU-privacy guarantee below depends on.
Admins can allow a personal vault on the managed profile for teams that prefer the convenience. Still zero-knowledge to the org — but you trade the “no personal data on the governed profile” guarantee for it.
A work vault carries an Org Recovery Key, so a quorum of your own officers can recover it — that is the point of a company vault. It is zero-knowledge to Veridenti, not to your organization. A personal vault has no recovery key at all: no one but the employee can open it, us included. We'd rather you read that here than discover it in a security review.
When someone leaves, you revoke the work profile and retain the work vault through the Org Recovery Key quorum — audited end to end. Their personal account, which lives elsewhere and which you never had access to, is untouched. Their bundled personal entitlement converts to a self-serve plan so they keep their own data. No personal MFA wiped, no lawsuit-shaped edge case.
Some credentials aren't personal and aren't SSO-able: service accounts, Wi-Fi and network gear, non-SSO vendor portals, API keys, break-glass. A narrow, org-owned Shared Team Vault handles those — explicit-add-only, ORK-retained, and fully audited.
For a works council (Betriebsrat), a DPO, or a GDPR Article 88 assessment, the hardest question is what employee personal data the employer's tools can reach. With Veridenti in isolate mode, the answer is none: the governed profile holds only company credentials, and the employee's personal vault is a separate account the employer has no key to. That shortens the DPIA and takes the fight out of the co-determination meeting. Pair it with country-level data residency that fails closed, and the DACH story is complete.
This guarantee applies in isolate mode. In coexist mode a personal vault does sit on the managed profile — still zero-knowledge to the org, but the “zero personal data on the governed profile” line no longer holds. Choose the trade deliberately.
Deploy from $3 per seat, or bring your security and privacy teams for a review.