Coverage modes & how your grade is calculated
Vigil scores your security posture 0–100 (A–F) across seven weighted domains. You choose how each domain is covered, and your grade is a weighted average over only the domains you cover — domains marked Managed or Not applicable are excluded entirely and never lower your score.
The six coverage modes
- API-verified — read live from a connected tenant (Microsoft 365, Google Workspace, AWS). The strongest evidence: machine-read, not self-reported, and defensible to an auditor.
- Provide config — you paste a real configuration export; Vigil's AI scores it.
- Auto-check (DNS) — Vigil reads your public DNS itself (SPF, DKIM, DMARC, MX, MTA-STS, TLS-RPT, BIMI). No export needed.
- Attest — you answer a short questionnaire. Scored as your own report, and labelled as self-attested rather than verified.
- Managed by provider — someone else runs this domain (your MSP, an MDR). Out of scope.
- Not applicable — the domain doesn't apply to you. Out of scope.
How the grade is calculated
Each domain carries a base weight: Identity & Access 20, Network 20, Endpoint 15, Cloud 15, Email Security 10, Data Protection 10, Monitoring & Logging 10.
Your overall score is a weighted average across only the covered domains, with their weights renormalized to sum to 100. Managed and Not-applicable domains are removed from both the numerator and the denominator — so scoping a domain out never helps or hurts your grade.
Worked example: if Identity (weight 20) scores 80 and Email (weight 10) scores 50 and everything else is Not applicable, your grade is not (80×20 + 50×10) / 100 = 21. The two weights (30) are rescaled to 100: (80×20 + 50×10) / 30 = 70/100.
Verified vs self-reported
Where a domain is covered by a connected tenant, Vigil uses the live scan result and badges it Verified with the provider and date. Everywhere else it uses your latest self-reported evidence. Both blend into one resolved grade, and each domain shows where its evidence came from.
If a domain is set to API-verified but no scan has run yet, it shows as Awaiting scan rather than being silently dropped or scored as zero.
Why Network is never API-verified
There's no read-only API for firewall and segmentation configuration, so Network stays paste-or-attest. Vigil labels this honestly rather than implying verification it can't perform.