A security overview for the people who sign off: how vaults are sealed on the device, what our servers can and cannot see, how a breach gets contained in one click — and where our compliance program honestly stands today.
Zero-knowledge, in plain language
“Zero-knowledge” is not a privacy policy. It is an order of operations: encrypt first, transmit second. Every credential is sealed on the user's device with a key derived from a master password we never receive. What travels — and what we store — is ciphertext.
The master password is stretched into an encryption key on the endpoint
(PBKDF2-SHA256 · 310k). Neither the password nor the key is ever transmitted.
Every entry is encrypted with AES-256-GCM — authenticated encryption, fresh IVs —
before a single byte leaves the device.
Our servers sync and back up ciphertext. There is no server-side decrypt path, no master key in escrow, no support back door.
The test that matters
Judge a zero-knowledge claim by its worst days, not its marketing. Run the three scenarios every security review should run — and notice that for Veridenti, all three converge on the same outcome.
“If our servers were breached tomorrow, the attacker would hold ciphertext they cannot decrypt. So would a court order. So would we. That is the entire point.”
Veridenti design principle № 1Differentiated controls
Encryption done right is table stakes. These are the controls that go further — shrinking the surface attackers can reach, containing the blast radius when a third party fails, and making your governance independently verifiable.
Vaults are sealed on-device; servers hold only ciphertext. Security posture is computed on the endpoint too — nothing leaves by default, and telemetry is strictly opt-in.
When a site changes its login form, Veridenti repairs the fill automatically — and fills only on the matching origin. People stay off the type-it-yourself, reuse-it-everywhere path.
A unique address per site means a vendor leak exposes exactly one relationship. Revoke the alias in one click; the phishing channel dies and every other account is untouched.
Reused, weak, breached, MFA-gapped, stale — scored on each device, aggregated as counts only, and rolled into one number your board can track quarter over quarter.
Account recovery requires a quorum of officers you designate. Veridenti holds no recovery key — so we cannot lose one, leak one, or be compelled to hand one over.
Every admin action is appended to a hash-chained log whose integrity anyone can verify — streamed to Splunk HEC, Datadog, or any SIEM via a generic HTTPS collector.
Containment, live
This is what the console shows the morning a third party discloses a breach: the exposure is already scoped to aliases, containment is one action, and the whole response lands in a log your auditors can verify — not just read.
Detection without disclosure: leaked-password and breached-domain monitoring is computed on the device against breach corpora — your people learn they're exposed without a server ever learning what they typed. No phone-home, even for the alarm bell.
An honest comparison
Leading enterprise password managers encrypt well; we're not going to pretend otherwise. This table shows where capabilities genuinely diverge — including the one place a typical suite does something we deliberately do differently.
| Capability | Veridenti | Typical enterprise manager |
|---|---|---|
| End-to-end encrypted vaultAES-256-GCM, keys derived on-device (PBKDF2-SHA256, 310k) | Table stakes — done well across the field | |
| No phone-home by defaultPosture computed on endpoints; telemetry strictly opt-in | —Posture & usage typically computed server-side | |
| Self-healing autofillBroken login forms repaired automatically; origin-bound fills | — | |
| Per-site masked email with 1-click killNative aliasing; breach contained to one vendor relationship | Usually via third-party alias integrations | |
| Board-reportable Human-Risk IndexOne trending number; scored on-device, aggregated as counts | Admin health scores, computed in the vendor cloud | |
| Breach & leak monitoringLeaked-password + breached-domain monitoring, computed on-device (no phone-home) | By design: detection without disclosure | Broader dark-web email monitoring, cloud-side |
| Customer-held M-of-N recoveryYour officers approve recovery; vendor holds no key | Admin-reset or vendor-assisted models common | |
| Tamper-evident, hash-chained auditLog integrity independently verifiable, not asserted | Audit logs exist; integrity rests on vendor trust | |
| SIEM streamingSplunk HEC & Datadog natively; Microsoft Sentinel and any SIEM via a generic HTTPS collector | Common at enterprise tiers | |
| SSO (SAML/OIDC) + SCIMIncluded on Enterprise plans (50+ seats); an at-cost add-on for smaller teams | Often gated to a premium tier |
Reflects publicly documented capabilities of leading enterprise password managers as of Q3 2026, generalized across the category. Where the field does something well — or takes an approach we chose against — this table says so. Bring your current vendor's datasheet to the demo; we'll walk it line by line.
Compliance, plainly
Security pages love the present tense. Here is ours with the tenses kept honest: what is live in production, what is in progress, and what is on the roadmap — so your due-diligence file matches reality on day one.
AES-256-GCM with on-device key derivation (PBKDF2-SHA256, 310,000 iterations). No plaintext key storage or logging; confirmed by internal security audit.
LiveAn enrolled (org-governed) profile carries an Org Recovery Key, so work vaults are recoverable by a quorum of your own officers (Shamir M-of-N, threshold ≥2) — that is what “work” means. Personal vaults carry no Org Recovery Key and are org-blind: Veridenti and the organization can decrypt neither. We do not claim work vaults are zero-knowledge to the organization; we claim they are zero-knowledge to us.
LiveHash-chained admin audit log, integrity-verifiable. Streams to Splunk HEC and Datadog natively; Microsoft Sentinel and any SIEM via a generic HTTPS collector.
LiveLeaked-password and breached-domain monitoring, computed on-device with no phone-home. We do not claim parity with cloud-side dark-web email monitoring — see the comparison above.
LiveVault data is region-pinned and fails closed — if the pinned region is unavailable, data does not silently fall back elsewhere. Global today; EU/US and per-country pinning on Enterprise contract.
On contractCounsel-approved Data Processing Agreement and Business Associate Agreement executed at contracting, alongside our security documentation pack.
At contractingReadiness program in progress — controls, policies, and continuous evidence collection are stood up; a Type I report is targeted first.
In progressPlanned; on the certification roadmap following SOC 2. Our ISMS policy pack is already written to align.
PlannedNext step
Bring your threat model, your auditor, and your hardest questions. We'll show the ciphertext, verify an audit chain live, and walk the comparison table against your current vendor — line by line.
Security review, scheduled this week.
Deep divesales@veridenti.com — architecture review with our engineers
Documentationveridenti.com/security — policies, disclosure program, this document
Start nowveridenti.com — deploy from $3/seat today