Sign InStart Free Trial

Security & Trust

Vigil is built by a security company for security-conscious buyers. Here's how we protect your data and our platform.

Your data isn't used to train models

Customer briefings, assessments, and configurations are never used to train AI models. Feed content (CISA KEV, NVD) is public; your inputs stay yours.

PII redaction before AI processing

Personal identifiers — email addresses, phone numbers, SSNs, payment-card-like numbers — are automatically redacted from the configuration and organization context sent to an AI model for posture assessments and threat briefings. Technical identifiers (IPs, hostnames, ARNs) are deliberately preserved so the analysis remains accurate.

Strict multi-tenant isolation

Every record is scoped to its organization. Briefings, assessments, findings, alerts, and settings are accessible only within the owning tenant, enforced on every request.

Modern authentication

Sessions use purpose-bound HMAC-signed cookies with argon2id password hashing (OWASP parameters), single-use email verification and login handoff tokens, and a session-revocation lever. Logins are rate-limited with unspoofable client identification.

Hardened by default

A per-request nonce-based Content-Security-Policy, HSTS, strict security headers, SSRF-guarded outbound webhooks, and a non-root container. The app requires no agents, no appliances, and no inbound network access to your environment.

Self-service and least-exposure

You choose exactly what to share. Posture assessments analyze only the configuration you paste in; nothing is pulled from your network.

SOC 2 Type II is in progress. For security questions or to request documentation, contact security@paliton.net.