Veridenti
Trust & Shared Responsibility

Security is a partnership. Here is the exact split — in plain language.

One page that says what Veridenti secures, what you secure, and what the key contract terms actually mean — including the one that matters most: your master password is yours alone, and we can never recover it.

VERIDENTI SECURES The service & its code Cryptography Blind-server architecture Availability · vulnerability mgmt YOU SECURE Your master password Your endpoints Who has access Timely offboarding VERIDENTI YOU ONE VAULT · TWO JOBS · NO FINE-PRINT SURPRISES
0secrets Veridenti can read — the servers hold ciphertext only
1master password. Only you hold it — and it is unrecoverable if lost
2sides to security. This page shows the exact split
100%of the binding terms live in your executed ToS & DPA — not here

This is a plain-language summary, not a contract. We wrote it so a CISO and a CFO can read the same page and reach the same understanding. The binding terms are those in your executed Terms of Service and Data Processing Agreement — where they differ from this page, the executed documents govern. Have your counsel review them; we expect nothing less.

The split

What we secure. What you secure.

Veridenti is built so that we cannot touch your secrets — which means some responsibilities can only ever be yours. That isn't fine print; it's the honest consequence of zero-knowledge design. Here is the whole division of labor, on one diagram.

VERIDENTI SECURES YOU SECURE The service & its code Secure development, testing & release of everything we ship. Cryptography Vetted, modern algorithms; keys derived and used only on your devices. Blind-server architecture Our servers store ciphertext they cannot read — by design, not by policy. Availability & resilience Uptime, encrypted backups, and region-pinned storage that fails closed. Vulnerability management Continuous monitoring, prompt patching, and coordinated disclosure. Your master password UNRECOVERABLE IF LOST It encrypts everything. We hold no copy and cannot reset it — keep your recovery kit safe. Your endpoints Decryption happens on your devices. Keep them patched, locked, and yours. Who gets in Strong MFA, sensible sessions, and regular reviews of who holds admin rights. Timely offboarding Remove seats the day people leave — SCIM automates deprovisioning on Enterprise. ! The trade, stated plainly A master password lost with no recovery kit means the vault is unrecoverable. By anyone. SHARED · COMPLIANCE We supply the controls and the evidence · you operate your program and own your regulatory obligations

Our side, in practice

  • If our servers are breached, the attacker holds ciphertext they cannot decrypt. So would we.
  • Residency fails closed: data is region-pinned; if a region is unavailable, writes stop rather than spill elsewhere.
  • Every admin action lands in a tamper-evident, hash-chained audit log you can verify independently.

Your side, in practice

  • Treat the master password like a house key — there is no locksmith. Save the recovery kit on day one.
  • A compromised endpoint sees what you see. No vault design survives malware with your unlocked session — patch and lock devices.
  • Offboard the same day. Access we can't see into is access only you can revoke on time.

The term that matters most

Unrecoverable is not a bug. It's the product.

Your master password is turned into an encryption key on your device and never leaves it. Veridenti keeps no copy — so there is no reset button, no support back-door, and nothing for an attacker, an insider, or a subpoena to extract. The same design that could lock you out is the one that locks everyone else out.

••••••••••••• → becomes your key, here Your device The only place the password exists CIPHERTEXT ONLY MASTER PASSWORD · NEVER TRANSMITTED No copy exists. Nothing to reset. Nothing to steal. Veridenti cloud Stores what it cannot read SAVE YOUR RECOVERY KIT ON DAY ONE · ORGS CAN ENABLE M-OF-N RECOVERY BY THEIR OWN OFFICERS — VERIDENTI STILL HOLDS NO KEY

“We cannot reset your master password. Not because we refuse — because we never had it. That is the deal: total privacy, and one key you genuinely have to keep.”

Veridenti trust principle № 1

The fine print, translated

Six terms, in words everyone can sign off on.

These are the clauses people usually skim — translated honestly. None of this replaces the executed documents; it exists so nobody is surprised by them.

The term What it means, plainly
Zero-knowledge & the unrecoverable master passwordArchitecture Your master password never leaves your device, so we can't read your vault — and can't reset the password. If you lose it without your recovery kit, your data is gone. Organizations can add M-of-N recovery approved by their own officers; Veridenti still holds no key.
No absolute securityHonesty clause No vendor can promise unbreakable security, and we don't. What we promise is a design where a breach of our servers yields unreadable ciphertext, plus the concrete controls and practices described on this page and in your agreement.
Service provided “as is”Standard licensing To the extent the law permits, the service is provided as-is, without implied warranties. This is standard software language. The commitments we do make — uptime, support, security practices — live explicitly in the executed ToS, DPA, and any SLA.
Limitation of liabilityStandard licensing Our financial liability is capped as set out in the ToS, with the caps and carve-outs stated there. Those numbers are negotiated in your executed agreement — read that document, not this summary, for the figures that bind.
DPA, subprocessors & BAAAt contracting Data-processing terms, the current subprocessor list, and — where applicable — a BAA are in preparation and provided at contracting. They define how personal data is handled, by whom, and under whose instructions.
Compliance is sharedShared We supply platform controls and evidence — tamper-evident audit, SIEM export, region pinning (SOC 2 readiness in progress, Type I targeted first; ISO 27001 planned). Your regulatory obligations — HIPAA, GDPR, sector rules — remain yours to operate. Veridenti is one strong control inside your program, not a substitute for it.

Our half of shared compliance

What we hand your auditors.

Shared responsibility only works if our half arrives as evidence, not adjectives. This is what the platform contributes to your control set today.

Zero-knowledge architecture

Vaults encrypt on-device; servers hold ciphertext only. No plaintext, no vendor-held keys, no phone-home by default.

Tamper-evident audit

Hash-chained, integrity-verifiable admin logs. Auditors verify the chain themselves — no “trust our export.”

SIEM streaming

Splunk HEC & Datadog natively; Microsoft Sentinel and any SIEM via a generic HTTPS collector.

Breach signals, on-device

Leaked-password and breached-domain monitoring, computed on the endpoint — findings without phone-home.

Data residency

Region-pinned storage that fails closed. Global today; EU/US and per-country pinning on Enterprise contract.

Identity plumbing

SSO (SAML/OIDC) + SCIM included on Enterprise plans (50+ seats); an at-cost add-on for smaller teams.

Certifications, stated exactly: SOC 2 readiness is in progress (Type I targeted first). ISO 27001 is planned on our roadmap. DPA and BAA are in preparation and provided at contracting. We will always state compliance status this precisely — if a claim on a vendor page can't be dated and evidenced, it shouldn't be there.

Your half, made easy

Four moments where your side happens.

Your responsibilities aren't a policy binder — they're four moments. Handle each one and your half of this page is done.

Day one

Set & save

Choose a strong master password and store the recovery kit somewhere safe. This is the one step no one can do for you.

Ongoing

Lock the doors

Enforce MFA (via SSO where you have it), keep endpoints patched and screen-locked, and review admin access on a schedule.

Departures

Offboard same-day

Remove seats when people leave and rotate anything they shared. SCIM deprovisions automatically on Enterprise plans.

If a device is lost

Revoke & relax

Revoke the device's sessions from the console. The vault on the device stays encrypted ciphertext without the master password.

Next step

Read the real thing.

This page is the map; your executed agreement is the territory. Send both to your counsel and your security team — if this summary and the contract ever tell different stories, tell us. We'll fix the page or the contract, whichever is wrong.

The binding documents Terms of Service · DPA & subprocessor list · BAA where applicable

At contractingDPA, subprocessors & BAA — in preparation, provided at contracting

Questionssecurity@veridenti.com — architecture, evidence, audit support

Termsveridenti.com/terms · veridenti.com/privacy