Sign InStart Free Trial

Security & Trust

Vigil is built by a security company for security-conscious buyers. Every control below is implemented in the product today — and where something isn’t built yet, we say so rather than leaving you to find out during diligence.

Looking for what we monitor and how findings are prioritized? See coverage & prioritization.

Authentication & access control

SSO — Google and Microsoft

Sign in with Google or Microsoft via OIDC, or with a password. Organizations that require MFA can optionally treat a verified SSO session as satisfying it, so you aren't forced to run two second factors.

TOTP multi-factor authentication

App-based TOTP (any authenticator), with single-use backup codes stored hashed. Owners can turn on organization-enforced MFA — every member is then blocked from the app and the API until they enrol.

Role-based access

Three roles — owner, admin and read-only. Invitations carry the role, so you can give an auditor or executive visibility without granting the ability to change settings or generate against your plan.

Password handling

argon2id hashing with OWASP-recommended parameters. New and changed passwords are screened against the Have I Been Pwned breach corpus using k-anonymity — only the first five characters of the hash prefix are sent, so the password itself never leaves Vigil.

Session and brute-force protection

Purpose-bound HMAC-signed session cookies with a revocation lever, single-use email-verification and password-reset tokens, per-account lockout on repeated failed logins, and rate limiting keyed on unspoofable client identification. New-device sign-ins trigger an alert email.

Data protection

Encryption

All traffic is TLS-encrypted and HSTS-enforced. Sensitive values are additionally encrypted at the application layer with AES-256-GCM before they reach the database: TOTP secrets, OAuth access and refresh tokens for connected tenants, and integration API tokens.

Strict multi-tenant isolation

Every record is scoped to its owning organization. Briefings, assessments, findings, alerts, connections and settings are reachable only within that tenant, enforced on every request rather than by client-side filtering.

Agentless by design — least exposure

No agents, no appliances, and no inbound network access to your environment. Vigil connects outbound over vendor APIs using the scopes you grant, which means there is no sensor to compromise and no listening port we ask you to open.

Your data is never used to train models

Customer briefings, assessments, configurations and connected-tenant data are never used to train AI models, by us or by our AI sub-processor under its enterprise terms.

PII redaction before AI processing

Personal identifiers — email addresses, phone numbers, national ID numbers and payment-card-like numbers — are automatically redacted from the context sent to an AI model. Technical identifiers such as IPs, hostnames and ARNs are deliberately preserved so the analysis stays accurate.

Platform hardening

Secure-by-default web layer

A per-request nonce-based Content-Security-Policy (no unsafe-inline scripts in production), strict transport and framing headers, and a non-root application container.

Guarded outbound requests

Webhook destinations you configure are SSRF-guarded, and links surfaced from external threat feeds are restricted to http(s) schemes before they are ever rendered.

Untrusted-input handling for AI

Threat-feed content and customer-supplied configuration are treated strictly as data, never as instructions. The analysis prompts state this explicitly to resist prompt-injection through a poisoned advisory or config file.

Integrity-checked evidence

A verified scan that evaluated nothing is rejected outright rather than being stored as a passing or failing grade, so the evidence you hand to an auditor reflects a check that actually ran.

Change history on findings

Every finding status change is recorded with the actor and timestamp — including system-generated transitions from re-assessment — giving you a defensible remediation trail.

Sub-processors

The third parties that may process customer data on our behalf. Threat feeds (CISA, NVD, FIRST/EPSS, GitHub, Have I Been Pwned and others) are read-only sources — we retrieve from them and send no customer data to them.

Sub-processorPurposeData processed
AnthropicAI analysis for briefings, assessments and roadmapsPII-redacted organization context and configuration; not used for training
Fly.ioApplication hosting and managed PostgreSQLAll application data at rest
ResendTransactional and briefing email deliveryRecipient email addresses and message content
StripeSubscription billingBilling contact and subscription state — card details go directly to Stripe and never touch Vigil

Data retention & deletion

Your data is retained for the life of your account so that posture trends and finding history remain intact. You can disconnect any integration at any time from Settings, which revokes our stored tokens. To export or permanently delete your organization’s data, email security@paliton.net — we remove it from production systems within 30 days and confirm in writing. Database backups are encrypted and taken daily on a rolling 5-day window, so any residual copy ages out within 5 days of that deletion. Self-service export and deletion are on the roadmap.

Vulnerability disclosure

Found a security issue? Report it to security@paliton.net. We acknowledge reports within two business days and will keep you updated until the issue is resolved. We will not pursue legal action against researchers who act in good faith: test only against your own account, avoid accessing other tenants’ data, don’t degrade the service, and give us reasonable time to remediate before disclosing. If we confirm and fix your report, we’re happy to credit you.

What we don’t have yet

We would rather you learn this here than in a questionnaire:

  • SOC 2 Type II — in progress; the report is not yet available.
  • Independent third-party penetration test — planned; no report is available today.
  • Account-level audit log covering every administrative action (finding-level history ships today).
  • SCIM / directory-based user provisioning and de-provisioning.
  • Self-service data export and deletion — handled by request today (see below).

For a security review, questionnaire or documentation request, contact security@paliton.net.