legal

Security

Last updated: August 25, 2026 · Hexasentra

Architecture

Hosted Vigil runs isolated per-customer scan workers. Repository content is processed in memory/temp storage and purged after each job. Findings store masked values by default.

Access control

Passwords are hashed with scrypt. Sessions are HttpOnly, Secure, SameSite cookies with 14-day expiry. Reveal actions are permissioned and audit-logged.

Transport & storage

All traffic over TLS 1.2+. Databases encrypted at rest. Secrets used by the service itself (tokens, webhooks) are stored in restricted-access configuration, never in code.

Sub-processors

Payment processing (Stripe), transactional email, and cloud hosting. No source code or findings are shared with sub-processors beyond hosting/email infrastructure.

Vulnerability disclosure

Found something in Vigil itself? Email security@hexasentra.com with details. We commit to acknowledging within 72 hours and will not pursue legal action for good-faith research within scope.

Compliance roadmap

SOC 2 Type II preparation underway for hosted plans.