Security at Vigil

Built to earn evidence—not invent trust.

Vigil applies layered controls to Slack delivery, administrator access, credentials, billing events, and training evidence. This page distinguishes implemented protections from future assurance work.

Last updated September 8, 2026
Current assurance status

Vigil is not currently claiming SOC 2, ISO 27001, HIPAA, or PCI DSS certification. Lesson coverage tags describe training topics; they are not certifications of Vigil or its customers.

Application controls

Verified Slack requests

Slack commands, events, and interactive actions require an HMAC signature and reject timestamps older than five minutes.

Protected billing events

Paddle webhook signatures are verified against the unmodified request body. Event identifiers are stored to prevent duplicate processing.

Encrypted credentials

Slack, Vanta, Drata, and customer-provided AI credentials are encrypted using AES-GCM before database storage.

Server-side integrations

Decrypted credentials are limited to server-to-server operations and are not returned to the browser after storage.

Least-privilege delivery

Vigil requests defined Slack scopes and keeps learner responses ephemeral where the workflow allows it.

Versioned evidence

Training records are designed to retain lesson version, score, attempt, learner, and completion timestamps.

Infrastructure and data protection

Vigil is designed to run on Cloudflare Workers with structured records in Cloudflare D1. Network traffic is served over HTTPS. Production credentials are stored as encrypted platform secrets, while customer-supplied integration credentials are encrypted at the application layer before persistence.

Access to production systems should be restricted to authorized operators using individual accounts, multifactor authentication, least privilege, and auditable change processes. Production and staging environments should use separate databases, credentials, Slack applications, and Paddle environments.

Customer responsibilities

  • Control administrator membership and remove access promptly during offboarding.
  • Configure Slack, Vanta, Drata, Paddle, and AI providers according to organizational policy.
  • Avoid placing unnecessary regulated or confidential data into custom lessons and AI prompts.
  • Review training assignments, evidence exports, retention settings, and integration destinations.
  • Report suspected compromise or incorrect permissions promptly.

Operational roadmap

Before general commercial availability, Vigil should complete independent penetration testing, dependency and secret scanning, incident-response exercises, documented backup and recovery testing, subprocessor review, access reviews, and a formal vulnerability-management program. Any external assurance report will be announced only after completion by a qualified independent assessor.

Responsible disclosure

If you believe you have discovered a vulnerability, do not access customer data, disrupt the service, or publicly disclose the issue before Vigil has had a reasonable opportunity to investigate. A dedicated security reporting address and safe-harbor policy will be published before commercial launch.