Vigil is not currently claiming SOC 2, ISO 27001, HIPAA, or PCI DSS certification. Lesson coverage tags describe training topics; they are not certifications of Vigil or its customers.
Application controls
Slack commands, events, and interactive actions require an HMAC signature and reject timestamps older than five minutes.
Paddle webhook signatures are verified against the unmodified request body. Event identifiers are stored to prevent duplicate processing.
Slack, Vanta, Drata, and customer-provided AI credentials are encrypted using AES-GCM before database storage.
Decrypted credentials are limited to server-to-server operations and are not returned to the browser after storage.
Vigil requests defined Slack scopes and keeps learner responses ephemeral where the workflow allows it.
Training records are designed to retain lesson version, score, attempt, learner, and completion timestamps.
Infrastructure and data protection
Vigil is designed to run on Cloudflare Workers with structured records in Cloudflare D1. Network traffic is served over HTTPS. Production credentials are stored as encrypted platform secrets, while customer-supplied integration credentials are encrypted at the application layer before persistence.
Access to production systems should be restricted to authorized operators using individual accounts, multifactor authentication, least privilege, and auditable change processes. Production and staging environments should use separate databases, credentials, Slack applications, and Paddle environments.
Customer responsibilities
- Control administrator membership and remove access promptly during offboarding.
- Configure Slack, Vanta, Drata, Paddle, and AI providers according to organizational policy.
- Avoid placing unnecessary regulated or confidential data into custom lessons and AI prompts.
- Review training assignments, evidence exports, retention settings, and integration destinations.
- Report suspected compromise or incorrect permissions promptly.
Operational roadmap
Before general commercial availability, Vigil should complete independent penetration testing, dependency and secret scanning, incident-response exercises, documented backup and recovery testing, subprocessor review, access reviews, and a formal vulnerability-management program. Any external assurance report will be announced only after completion by a qualified independent assessor.
Responsible disclosure
If you believe you have discovered a vulnerability, do not access customer data, disrupt the service, or publicly disclose the issue before Vigil has had a reasonable opportunity to investigate. A dedicated security reporting address and safe-harbor policy will be published before commercial launch.