Docs
Setup guides for connecting your tenants read-only, and a plain explanation of how Vigil scores your posture. Every connection is agentless and read-only — Vigil never writes to your environment.
Connect Google Workspace
Vigil assesses Google Workspace against CISA's SCuBA Secure Configuration Baselines using ScubaGoggles. It connects through a read-only service account with domain-wide delegation — your super admin authorizes Vigil's service-account client ID and a fixed list of read-only scopes once, and Vigil never writes to your tenant.
Connect Microsoft 365
Vigil assesses Microsoft 365 against CISA's SCuBA Secure Configuration Baselines using ScubaGear. It connects via Microsoft's admin-consent flow with read-only application permissions — a Global Administrator grants consent once, and Vigil never writes to your tenant.
Connect AWS
Vigil assesses AWS with Prowler against CIS, NIST and PCI benchmarks. It connects through a read-only cross-account IAM role gated by a unique external ID — Vigil never stores your AWS keys.
Coverage modes & how your grade is calculated
Vigil scores your security posture 0–100 (A–F) across seven weighted domains. You choose how each domain is covered, and your grade is a weighted average over only the domains you cover — domains marked Managed or Not applicable are excluded entirely and never lower your score.
Fix a quantum-vulnerable TLS endpoint (hybrid key exchange)
If Vigil flagged an external endpoint as quantum-vulnerable, the fix is to enable hybrid key exchange (X25519MLKEM768) wherever TLS terminates. On Cloudflare it's already the default; if you control your own edge it's a config change; and if your host terminates TLS for you, you can't set it at all — this guide covers all three cases and how to verify the result.
Looking for a definition instead? Security glossary · Security & Trust