Start free for 14 days. Upgrade when your first verified alert saves your quarter.
Vigil clones full git history (including force-pushed refs and gists) of the repositories belonging to your organizations and discovered employee accounts, applies curated high-value credential detectors, eliminates documented dummy values, sample files and expired material, then verifies survivors directly with the provider.
Yes. Vigil monitors sources you own or are authorized to monitor, and verifies candidates using safe read-only provider endpoints. We never authenticate into third-party systems, never send data anywhere, and encourage responsible handling of any finding.
Each credential type has a purpose-built verifier hitting a read-only endpoint — e.g. AWS STS GetCallerIdentity, Stripe /balance, Slack auth.test. Results are one of: LIVE, INVALID, or NOT PROBED BY DESIGN (for write-only token types).
No. Findings are stored masked by default; full values require explicit reveal permission and are audit-logged. See our Security page for the full model.
Yes — Lifetime plans include source access and setup docs for running Vigil entirely inside your own infrastructure, air-gapped if needed.
Hosted plans always run the latest engine. Lifetime Pro includes 12 months of detector and verifier updates; Lite includes the engine at purchase time.