Veridenti
Security Overview · Enterprise

Every vendor says “zero-knowledge.” Veridenti is built so you never have to take our word for it.

A security overview for the people who sign off: how vaults are sealed on the device, what our servers can and cannot see, how a breach gets contained in one click — and where our compliance program honestly stands today.

Zero-Knowledge
SEALED ON DEVICE
encrypted before it ever leaves your device
your key never leaves
Veridenti Cloud
stores ciphertext only · cannot read it
0plaintext secrets our servers can read, hold, or disclose
AES-256-GCMon-device encryption · PBKDF2-SHA256, 310,000 iterations
M-of-Norg recovery approved by your officers — we hold no key
100%of admin actions land in a tamper-evident, hash-chained log

Zero-knowledge, in plain language

The secret is sealed before it ever leaves the laptop.

“Zero-knowledge” is not a privacy policy. It is an order of operations: encrypt first, transmit second. Every credential is sealed on the user's device with a key derived from a master password we never receive. What travels — and what we store — is ciphertext.

1

The device derives the key

The master password is stretched into an encryption key on the endpoint (PBKDF2-SHA256 · 310k). Neither the password nor the key is ever transmitted.

2

The vault is sealed locally

Every entry is encrypted with AES-256-GCM — authenticated encryption, fresh IVs — before a single byte leaves the device.

3

The cloud stores what it can't read

Our servers sync and back up ciphertext. There is no server-side decrypt path, no master key in escrow, no support back door.

Your device Key derivation + encryption, local VAULT KEY 9f2c·e81b·44aa·07d3 b6e0·1f9d·c25a·88e4 73aa·d90f·5be2·c614 Ciphertext only, end to end Veridenti cloud Stores what it cannot read TLS TLS NO PHONE-HOME BY DEFAULT · NO VENDOR-HELD KEYS · NO SERVER-SIDE DECRYPT PATH

The test that matters

A breach, a subpoena, an insider. Same answer.

Judge a zero-knowledge claim by its worst days, not its marketing. Run the three scenarios every security review should run — and notice that for Veridenti, all three converge on the same outcome.

Our servers are breached Attacker exfiltrates the vault store We receive a legal demand Subpoena compels everything we hold One of our own goes rogue Insider with full production access e91b·30fa·6c2d·b874 7d05·af92·c1e6·044b bc38·52e0·9ad1·f76c Ciphertext. Every time. No key exists on our side to steal, compel, or abuse. THE SAME QUESTION, ASKED THREE WAYS — WITH ONE ARCHITECTURAL ANSWER

“If our servers were breached tomorrow, the attacker would hold ciphertext they cannot decrypt. So would a court order. So would we. That is the entire point.”

Veridenti design principle № 1

Differentiated controls

Six controls most vaults don't have.

Encryption done right is table stakes. These are the controls that go further — shrinking the surface attackers can reach, containing the blast radius when a third party fails, and making your governance independently verifiable.

Zero-knowledge, no phone-home

Vaults are sealed on-device; servers hold only ciphertext. Security posture is computed on the endpoint too — nothing leaves by default, and telemetry is strictly opt-in.

Self-healing autofill

When a site changes its login form, Veridenti repairs the fill automatically — and fills only on the matching origin. People stay off the type-it-yourself, reuse-it-everywhere path.

Masked email + 1-click containment

A unique address per site means a vendor leak exposes exactly one relationship. Revoke the alias in one click; the phishing channel dies and every other account is untouched.

Board-reportable Human-Risk Index

Reused, weak, breached, MFA-gapped, stale — scored on each device, aggregated as counts only, and rolled into one number your board can track quarter over quarter.

Org recovery: M-of-N, your officers

Account recovery requires a quorum of officers you designate. Veridenti holds no recovery key — so we cannot lose one, leak one, or be compelled to hand one over.

Tamper-evident, hash-chained audit

Every admin action is appended to a hash-chained log whose integrity anyone can verify — streamed to Splunk HEC, Datadog, or any SIEM via a generic HTTPS collector.

Containment, live

From “a vendor leaked” to “contained” in one click.

This is what the console shows the morning a third party discloses a breach: the exposure is already scoped to aliases, containment is one action, and the whole response lands in a log your auditors can verify — not just read.

Veridenti Console — Breach Containment Tue 09:14 · 412 seats travelvendor.com disclosed a breach Flagged on-device across your fleet · exposure already scoped to masked aliases 14 aliases affected 0 real addresses exposed Revoke all 14 → Contained 09:14:36 — aliases revoked · rotation queued · phishing channel closed. TAMPER-EVIDENT AUDIT TRAIL Chain verified ✓ 09:14:08 breach.flagged travelvendor.com #7c1e…a940 09:14:36 aliases.revoked ×14 · admin j.chen #d02f…7c1e 09:14:37 rotation.queued 14 credentials #f4b8…d02f Each entry commits to the hash of the one before it — streaming to Splunk HEC · Datadog · your SIEM Detection computed on-device · console sees counts and aliases, never credentials
  • The blast radius is pre-shrunk. Because every vendor got a unique alias, the breach maps to 14 revocable addresses — not 412 identical inboxes.
  • Containment is an action, not a project. One click revokes the aliases and queues credential rotation. Incident response measured in seconds, not standups.
  • The evidence writes itself. Every step lands in the hash-chained log — integrity-verifiable by your auditor, streamed to your SIEM as it happens.

Detection without disclosure: leaked-password and breached-domain monitoring is computed on the device against breach corpora — your people learn they're exposed without a server ever learning what they typed. No phone-home, even for the alarm bell.

An honest comparison

Where the field is good — and where it stops.

Leading enterprise password managers encrypt well; we're not going to pretend otherwise. This table shows where capabilities genuinely diverge — including the one place a typical suite does something we deliberately do differently.

Included Partial / different approach   Not offered
Capability Veridenti Typical enterprise manager
End-to-end encrypted vaultAES-256-GCM, keys derived on-device (PBKDF2-SHA256, 310k) Table stakes — done well across the field
No phone-home by defaultPosture computed on endpoints; telemetry strictly opt-in Posture & usage typically computed server-side
Self-healing autofillBroken login forms repaired automatically; origin-bound fills
Per-site masked email with 1-click killNative aliasing; breach contained to one vendor relationship Usually via third-party alias integrations
Board-reportable Human-Risk IndexOne trending number; scored on-device, aggregated as counts Admin health scores, computed in the vendor cloud
Breach & leak monitoringLeaked-password + breached-domain monitoring, computed on-device (no phone-home) By design: detection without disclosure Broader dark-web email monitoring, cloud-side
Customer-held M-of-N recoveryYour officers approve recovery; vendor holds no key Admin-reset or vendor-assisted models common
Tamper-evident, hash-chained auditLog integrity independently verifiable, not asserted Audit logs exist; integrity rests on vendor trust
SIEM streamingSplunk HEC & Datadog natively; Microsoft Sentinel and any SIEM via a generic HTTPS collector Common at enterprise tiers
SSO (SAML/OIDC) + SCIMIncluded on Enterprise plans (50+ seats); an at-cost add-on for smaller teams Often gated to a premium tier

Reflects publicly documented capabilities of leading enterprise password managers as of Q3 2026, generalized across the category. Where the field does something well — or takes an approach we chose against — this table says so. Bring your current vendor's datasheet to the demo; we'll walk it line by line.

Compliance, plainly

Where we stand today. No asterisks.

Security pages love the present tense. Here is ours with the tenses kept honest: what is live in production, what is in progress, and what is on the roadmap — so your due-diligence file matches reality on day one.

Vault encryption

AES-256-GCM with on-device key derivation (PBKDF2-SHA256, 310,000 iterations). No plaintext key storage or logging; confirmed by internal security audit.

Live

Work/personal trust boundary

An enrolled (org-governed) profile carries an Org Recovery Key, so work vaults are recoverable by a quorum of your own officers (Shamir M-of-N, threshold ≥2) — that is what “work” means. Personal vaults carry no Org Recovery Key and are org-blind: Veridenti and the organization can decrypt neither. We do not claim work vaults are zero-knowledge to the organization; we claim they are zero-knowledge to us.

Live

Tamper-evident audit + SIEM

Hash-chained admin audit log, integrity-verifiable. Streams to Splunk HEC and Datadog natively; Microsoft Sentinel and any SIEM via a generic HTTPS collector.

Live

Breach monitoring

Leaked-password and breached-domain monitoring, computed on-device with no phone-home. We do not claim parity with cloud-side dark-web email monitoring — see the comparison above.

Live

Data residency

Vault data is region-pinned and fails closed — if the pinned region is unavailable, data does not silently fall back elsewhere. Global today; EU/US and per-country pinning on Enterprise contract.

On contract

DPA & BAA

Counsel-approved Data Processing Agreement and Business Associate Agreement executed at contracting, alongside our security documentation pack.

At contracting

SOC 2

Readiness program in progress — controls, policies, and continuous evidence collection are stood up; a Type I report is targeted first.

In progress

ISO 27001

Planned; on the certification roadmap following SOC 2. Our ISMS policy pack is already written to align.

Planned

Next step

Put the architecture in front of your security team.

Bring your threat model, your auditor, and your hardest questions. We'll show the ciphertext, verify an audit chain live, and walk the comparison table against your current vendor — line by line.

Security review, scheduled this week.


Deep divesales@veridenti.com — architecture review with our engineers

Documentationveridenti.com/security — policies, disclosure program, this document

Start nowveridenti.com — deploy from $3/seat today