Sign InStart Free Trial

Coverage & Prioritization

Exactly what Vigil watches, how often, and how it decides what deserves your attention — including what we deliberately don’t do.

How prioritization works

“AI-powered” isn’t an answer, so here is the actual mechanism. Every incoming item is scored on three inputs before it ever reaches you. The matching itself is deterministic and explainable — not a model guess — and every alert carries a plain-English reason for why you are seeing it.

Is it actually being exploited?

Membership of the CISA Known Exploited Vulnerabilities catalogue is the strongest single signal. We also merge VulnCheck's community KEV, which frequently lists exploitation before CISA does — those are flagged as early warnings so you aren't waiting on a catalogue update.

How likely is exploitation?

Every CVE is enriched with its EPSS score — the FIRST-published probability, from 0 to 1, that it will be exploited in the next 30 days. This is what stops a CVSS 9.8 with a 0.2% exploit probability outranking a CVSS 7.5 that is 90% likely to be hit.

Does it touch your stack?

Findings are matched against the vendors and products you actually run, recorded during onboarding and editable at any time. Matching is whole-word and alias-aware, so "AWS" matches Amazon Web Services but not "laws". If it doesn't touch your estate, it doesn't reach you — that is the whole point.

What wakes you up — and what doesn’t

An alerting product earns trust by staying quiet. Two tiers, on purpose:

  • Immediate notification — critical, stack-matched threats, and anything linked to an active ransomware campaign that touches technology you run. These reach email, Slack and Microsoft Teams as they happen.
  • In-app and weekly briefing — sector ransomware activity and breach exposure. These are awareness signals matched on your industry or your vendors rather than an exploitable hole in your estate, so they are never paged at 2am.

Intelligence sources

SourceWhat it contributesRefresh
CISA KEVVulnerabilities confirmed exploited in the wildEvery 6 hours
VulnCheck Community KEVExploited CVEs, often ahead of CISA listingEvery 6 hours
NIST NVDNewly published high and critical CVEsEvery 6 hours
CISA AdvisoriesCampaign, vendor and hardening advisoriesEvery 6 hours
GitHub Security AdvisoriesReviewed package and product vulnerabilitiesEvery 6 hours
FIRST EPSSExploit-probability enrichment for every CVEEvery 6 hours
Ransomware.liveRansomware-group victim claims, matched to your sectorEvery 6 hours
Have I Been PwnedBreach corpora covering services in your stack and your own domainEvery 6 hours

Feeds are read-only: we retrieve from them and send no customer data to them. See Security & Trust for sub-processors and data handling.

Verified posture coverage

Verified posture means an API-connected check actually ran against your tenant — not a checkbox you ticked. Anything not covered by a live check can be attested manually, and the two are labelled differently so you and your auditor always know which is which.

PlatformHow it's checkedStatus
Microsoft 365CISA SCuBA baselines (ScubaGear), agentless via Graph APILive
Google WorkspaceCISA SCuBA baselines (ScubaGoggles), agentless via APILive
Amazon Web ServicesProwler checks via a read-only cross-account roleLive
Azure / Google CloudVerified posture checksRoadmap
Endpoint / OS hardeningOpenSCAP upload-and-ingestRoadmap

Scored across seven domains — Identity, Network, Endpoint, Email, Cloud, Data Protection, and Monitoring & Logging — and mapped to NIST CSF 2.0, CIS Controls v8, MITRE ATT&CK (Enterprise v19), HIPAA, PCI DSS 4.0 and CMMC. Domains you don’t have evidence for are marked out of scope rather than scored as failures.

Discovery & delivery

Vigil discovers your public footprint passively from DNS and certificate-transparency logs, so your stack profile stays current without you maintaining a spreadsheet. Findings and briefings are delivered in-app, by email, and to Slack or Microsoft Teams, with PDF export for board and audit reporting.

What Vigil does not do

  • No agents, sensors or appliances — and none are planned. Vigil is agentless by design.
  • No penetration testing or exploit validation. We do not attack your systems to prove a finding.
  • No patch deployment, configuration changes or autonomous remediation. Vigil tells you what to fix; you stay in control of the change.
  • No endpoint telemetry or EDR. We do not replace your endpoint security tooling.
  • No internal network scanning. Everything is API-connected and outbound-only.
  • Compliance readiness, not certification. Vigil produces the evidence an auditor accepts — it does not issue an attestation.

Questions about coverage for your environment? Email sales@paliton.net or start a 14-day trial.