Coverage & Prioritization
Exactly what Vigil watches, how often, and how it decides what deserves your attention — including what we deliberately don’t do.
How prioritization works
“AI-powered” isn’t an answer, so here is the actual mechanism. Every incoming item is scored on three inputs before it ever reaches you. The matching itself is deterministic and explainable — not a model guess — and every alert carries a plain-English reason for why you are seeing it.
Is it actually being exploited?
Membership of the CISA Known Exploited Vulnerabilities catalogue is the strongest single signal. We also merge VulnCheck's community KEV, which frequently lists exploitation before CISA does — those are flagged as early warnings so you aren't waiting on a catalogue update.
How likely is exploitation?
Every CVE is enriched with its EPSS score — the FIRST-published probability, from 0 to 1, that it will be exploited in the next 30 days. This is what stops a CVSS 9.8 with a 0.2% exploit probability outranking a CVSS 7.5 that is 90% likely to be hit.
Does it touch your stack?
Findings are matched against the vendors and products you actually run, recorded during onboarding and editable at any time. Matching is whole-word and alias-aware, so "AWS" matches Amazon Web Services but not "laws". If it doesn't touch your estate, it doesn't reach you — that is the whole point.
What wakes you up — and what doesn’t
An alerting product earns trust by staying quiet. Two tiers, on purpose:
- Immediate notification — critical, stack-matched threats, and anything linked to an active ransomware campaign that touches technology you run. These reach email, Slack and Microsoft Teams as they happen.
- In-app and weekly briefing — sector ransomware activity and breach exposure. These are awareness signals matched on your industry or your vendors rather than an exploitable hole in your estate, so they are never paged at 2am.
Intelligence sources
| Source | What it contributes | Refresh |
|---|---|---|
| CISA KEV | Vulnerabilities confirmed exploited in the wild | Every 6 hours |
| VulnCheck Community KEV | Exploited CVEs, often ahead of CISA listing | Every 6 hours |
| NIST NVD | Newly published high and critical CVEs | Every 6 hours |
| CISA Advisories | Campaign, vendor and hardening advisories | Every 6 hours |
| GitHub Security Advisories | Reviewed package and product vulnerabilities | Every 6 hours |
| FIRST EPSS | Exploit-probability enrichment for every CVE | Every 6 hours |
| Ransomware.live | Ransomware-group victim claims, matched to your sector | Every 6 hours |
| Have I Been Pwned | Breach corpora covering services in your stack and your own domain | Every 6 hours |
Feeds are read-only: we retrieve from them and send no customer data to them. See Security & Trust for sub-processors and data handling.
Verified posture coverage
Verified posture means an API-connected check actually ran against your tenant — not a checkbox you ticked. Anything not covered by a live check can be attested manually, and the two are labelled differently so you and your auditor always know which is which.
| Platform | How it's checked | Status |
|---|---|---|
| Microsoft 365 | CISA SCuBA baselines (ScubaGear), agentless via Graph API | Live |
| Google Workspace | CISA SCuBA baselines (ScubaGoggles), agentless via API | Live |
| Amazon Web Services | Prowler checks via a read-only cross-account role | Live |
| Azure / Google Cloud | Verified posture checks | Roadmap |
| Endpoint / OS hardening | OpenSCAP upload-and-ingest | Roadmap |
Scored across seven domains — Identity, Network, Endpoint, Email, Cloud, Data Protection, and Monitoring & Logging — and mapped to NIST CSF 2.0, CIS Controls v8, MITRE ATT&CK (Enterprise v19), HIPAA, PCI DSS 4.0 and CMMC. Domains you don’t have evidence for are marked out of scope rather than scored as failures.
Discovery & delivery
Vigil discovers your public footprint passively from DNS and certificate-transparency logs, so your stack profile stays current without you maintaining a spreadsheet. Findings and briefings are delivered in-app, by email, and to Slack or Microsoft Teams, with PDF export for board and audit reporting.
What Vigil does not do
- No agents, sensors or appliances — and none are planned. Vigil is agentless by design.
- No penetration testing or exploit validation. We do not attack your systems to prove a finding.
- No patch deployment, configuration changes or autonomous remediation. Vigil tells you what to fix; you stay in control of the change.
- No endpoint telemetry or EDR. We do not replace your endpoint security tooling.
- No internal network scanning. Everything is API-connected and outbound-only.
- Compliance readiness, not certification. Vigil produces the evidence an auditor accepts — it does not issue an attestation.
Questions about coverage for your environment? Email sales@paliton.net or start a 14-day trial.