One page that says what Veridenti secures, what you secure, and what the key contract terms actually mean — including the one that matters most: your master password is yours alone, and we can never recover it.
This is a plain-language summary, not a contract. We wrote it so a CISO and a CFO can read the same page and reach the same understanding. The binding terms are those in your executed Terms of Service and Data Processing Agreement — where they differ from this page, the executed documents govern. Have your counsel review them; we expect nothing less.
The split
Veridenti is built so that we cannot touch your secrets — which means some responsibilities can only ever be yours. That isn't fine print; it's the honest consequence of zero-knowledge design. Here is the whole division of labor, on one diagram.
The term that matters most
Your master password is turned into an encryption key on your device and never leaves it. Veridenti keeps no copy — so there is no reset button, no support back-door, and nothing for an attacker, an insider, or a subpoena to extract. The same design that could lock you out is the one that locks everyone else out.
“We cannot reset your master password. Not because we refuse — because we never had it. That is the deal: total privacy, and one key you genuinely have to keep.”
Veridenti trust principle № 1The fine print, translated
These are the clauses people usually skim — translated honestly. None of this replaces the executed documents; it exists so nobody is surprised by them.
| The term | What it means, plainly |
|---|---|
| Zero-knowledge & the unrecoverable master passwordArchitecture | Your master password never leaves your device, so we can't read your vault — and can't reset the password. If you lose it without your recovery kit, your data is gone. Organizations can add M-of-N recovery approved by their own officers; Veridenti still holds no key. |
| No absolute securityHonesty clause | No vendor can promise unbreakable security, and we don't. What we promise is a design where a breach of our servers yields unreadable ciphertext, plus the concrete controls and practices described on this page and in your agreement. |
| Service provided “as is”Standard licensing | To the extent the law permits, the service is provided as-is, without implied warranties. This is standard software language. The commitments we do make — uptime, support, security practices — live explicitly in the executed ToS, DPA, and any SLA. |
| Limitation of liabilityStandard licensing | Our financial liability is capped as set out in the ToS, with the caps and carve-outs stated there. Those numbers are negotiated in your executed agreement — read that document, not this summary, for the figures that bind. |
| DPA, subprocessors & BAAAt contracting | Data-processing terms, the current subprocessor list, and — where applicable — a BAA are in preparation and provided at contracting. They define how personal data is handled, by whom, and under whose instructions. |
| Compliance is sharedShared | We supply platform controls and evidence — tamper-evident audit, SIEM export, region pinning (SOC 2 readiness in progress, Type I targeted first; ISO 27001 planned). Your regulatory obligations — HIPAA, GDPR, sector rules — remain yours to operate. Veridenti is one strong control inside your program, not a substitute for it. |
Our half of shared compliance
Shared responsibility only works if our half arrives as evidence, not adjectives. This is what the platform contributes to your control set today.
Vaults encrypt on-device; servers hold ciphertext only. No plaintext, no vendor-held keys, no phone-home by default.
Hash-chained, integrity-verifiable admin logs. Auditors verify the chain themselves — no “trust our export.”
Splunk HEC & Datadog natively; Microsoft Sentinel and any SIEM via a generic HTTPS collector.
Leaked-password and breached-domain monitoring, computed on the endpoint — findings without phone-home.
Region-pinned storage that fails closed. Global today; EU/US and per-country pinning on Enterprise contract.
SSO (SAML/OIDC) + SCIM included on Enterprise plans (50+ seats); an at-cost add-on for smaller teams.
Certifications, stated exactly: SOC 2 readiness is in progress (Type I targeted first). ISO 27001 is planned on our roadmap. DPA and BAA are in preparation and provided at contracting. We will always state compliance status this precisely — if a claim on a vendor page can't be dated and evidenced, it shouldn't be there.
Your half, made easy
Your responsibilities aren't a policy binder — they're four moments. Handle each one and your half of this page is done.
Choose a strong master password and store the recovery kit somewhere safe. This is the one step no one can do for you.
Enforce MFA (via SSO where you have it), keep endpoints patched and screen-locked, and review admin access on a schedule.
Remove seats when people leave and rotate anything they shared. SCIM deprovisions automatically on Enterprise plans.
Revoke the device's sessions from the console. The vault on the device stays encrypted ciphertext without the master password.
Next step
This page is the map; your executed agreement is the territory. Send both to your counsel and your security team — if this summary and the contract ever tell different stories, tell us. We'll fix the page or the contract, whichever is wrong.
At contractingDPA, subprocessors & BAA — in preparation, provided at contracting
Questionssecurity@veridenti.com — architecture, evidence, audit support
Termsveridenti.com/terms · veridenti.com/privacy
This document is provided for convenience only. It summarizes, in ordinary language, how responsibility is shared between Veridenti and its customers and what certain contractual terms mean. It is not an offer, a warranty, or a modification of any agreement, and it creates no rights or obligations.
The binding terms are exclusively those set out in your executed Terms of Service, Data Processing Agreement, and any other agreements signed by both parties. Where this summary and an executed document differ, the executed document governs in every case. Please have your legal counsel review the executed documents before relying on them.