Security & Trust
Vigil is built by a security company for security-conscious buyers. Every control below is implemented in the product today — and where something isn’t built yet, we say so rather than leaving you to find out during diligence.
Looking for what we monitor and how findings are prioritized? See coverage & prioritization.
Authentication & access control
SSO — Google and Microsoft
Sign in with Google or Microsoft via OIDC, or with a password. Organizations that require MFA can optionally treat a verified SSO session as satisfying it, so you aren't forced to run two second factors.
TOTP multi-factor authentication
App-based TOTP (any authenticator), with single-use backup codes stored hashed. Owners can turn on organization-enforced MFA — every member is then blocked from the app and the API until they enrol.
Role-based access
Three roles — owner, admin and read-only. Invitations carry the role, so you can give an auditor or executive visibility without granting the ability to change settings or generate against your plan.
Password handling
argon2id hashing with OWASP-recommended parameters. New and changed passwords are screened against the Have I Been Pwned breach corpus using k-anonymity — only the first five characters of the hash prefix are sent, so the password itself never leaves Vigil.
Session and brute-force protection
Purpose-bound HMAC-signed session cookies with a revocation lever, single-use email-verification and password-reset tokens, per-account lockout on repeated failed logins, and rate limiting keyed on unspoofable client identification. New-device sign-ins trigger an alert email.
Data protection
Encryption
All traffic is TLS-encrypted and HSTS-enforced. Sensitive values are additionally encrypted at the application layer with AES-256-GCM before they reach the database: TOTP secrets, OAuth access and refresh tokens for connected tenants, and integration API tokens.
Strict multi-tenant isolation
Every record is scoped to its owning organization. Briefings, assessments, findings, alerts, connections and settings are reachable only within that tenant, enforced on every request rather than by client-side filtering.
Agentless by design — least exposure
No agents, no appliances, and no inbound network access to your environment. Vigil connects outbound over vendor APIs using the scopes you grant, which means there is no sensor to compromise and no listening port we ask you to open.
Your data is never used to train models
Customer briefings, assessments, configurations and connected-tenant data are never used to train AI models, by us or by our AI sub-processor under its enterprise terms.
PII redaction before AI processing
Personal identifiers — email addresses, phone numbers, national ID numbers and payment-card-like numbers — are automatically redacted from the context sent to an AI model. Technical identifiers such as IPs, hostnames and ARNs are deliberately preserved so the analysis stays accurate.
Platform hardening
Secure-by-default web layer
A per-request nonce-based Content-Security-Policy (no unsafe-inline scripts in production), strict transport and framing headers, and a non-root application container.
Guarded outbound requests
Webhook destinations you configure are SSRF-guarded, and links surfaced from external threat feeds are restricted to http(s) schemes before they are ever rendered.
Untrusted-input handling for AI
Threat-feed content and customer-supplied configuration are treated strictly as data, never as instructions. The analysis prompts state this explicitly to resist prompt-injection through a poisoned advisory or config file.
Integrity-checked evidence
A verified scan that evaluated nothing is rejected outright rather than being stored as a passing or failing grade, so the evidence you hand to an auditor reflects a check that actually ran.
Change history on findings
Every finding status change is recorded with the actor and timestamp — including system-generated transitions from re-assessment — giving you a defensible remediation trail.
Sub-processors
The third parties that may process customer data on our behalf. Threat feeds (CISA, NVD, FIRST/EPSS, GitHub, Have I Been Pwned and others) are read-only sources — we retrieve from them and send no customer data to them.
| Sub-processor | Purpose | Data processed |
|---|---|---|
| Anthropic | AI analysis for briefings, assessments and roadmaps | PII-redacted organization context and configuration; not used for training |
| Fly.io | Application hosting and managed PostgreSQL | All application data at rest |
| Resend | Transactional and briefing email delivery | Recipient email addresses and message content |
| Stripe | Subscription billing | Billing contact and subscription state — card details go directly to Stripe and never touch Vigil |
Data retention & deletion
Your data is retained for the life of your account so that posture trends and finding history remain intact. You can disconnect any integration at any time from Settings, which revokes our stored tokens. To export or permanently delete your organization’s data, email security@paliton.net — we remove it from production systems within 30 days and confirm in writing. Database backups are encrypted and taken daily on a rolling 5-day window, so any residual copy ages out within 5 days of that deletion. Self-service export and deletion are on the roadmap.
Vulnerability disclosure
Found a security issue? Report it to security@paliton.net. We acknowledge reports within two business days and will keep you updated until the issue is resolved. We will not pursue legal action against researchers who act in good faith: test only against your own account, avoid accessing other tenants’ data, don’t degrade the service, and give us reasonable time to remediate before disclosing. If we confirm and fix your report, we’re happy to credit you.
What we don’t have yet
We would rather you learn this here than in a questionnaire:
- SOC 2 Type II — in progress; the report is not yet available.
- Independent third-party penetration test — planned; no report is available today.
- Account-level audit log covering every administrative action (finding-level history ships today).
- SCIM / directory-based user provisioning and de-provisioning.
- Self-service data export and deletion — handled by request today (see below).
For a security review, questionnaire or documentation request, contact security@paliton.net.