product

Everything Vigil watches,
so you don't have to

☁️

Cloud infrastructure credentials

AWS key pairs (verified via STS GetCallerIdentity with SigV4), Azure storage keys and SAS tokens, Google service-account JSON keys and billable-API detection for client keys.

💳

Money-touching SaaS

Stripe live secret keys (balance check), PayPal-class payment tokens, Shopify admin tokens. Live keys here mean direct financial exposure.

🤖

AI & messaging platforms

OpenAI, Anthropic, DeepSeek-class keys, Slack workspace tokens, Telegram bot tokens, Twilio accounts, SendGrid senders, Mailgun domains.

📦

Supply-chain registries

npm publish tokens, PyPI upload tokens, Docker Hub PATs — the exact classes behind $14k–$31k bounty payouts and real package-takeover incidents.

🗄️

Databases & infrastructure

MongoDB Atlas URIs, PostgreSQL/MySQL/Redis connection strings, Kubernetes service account tokens, private key blocks, Grafana service accounts.

🧠

Intelligence layer

Ownership attribution, duplicate collapsing across history, severity scoring with plain-English reasons, per-finding report drafts your team can act on immediately.

What we deliberately DON'T flag

Client-side identifiers that ship inside every mobile/web app (Firebase API keys), Microsoft's documented emulator constants, tutorial tokens, .env.example files, docstring examples, vendored dependencies, expired JWTs, planted credential-corpus repos. This is where other tools generate 90% of their noise — and it's filtered before you ever see it.