Vigil subprocessors

The services behind Vigil, listed plainly.

This page identifies the providers Vigil uses to operate the service and distinguishes them from platforms or integrations a customer chooses to connect.

Effective and last updated September 26, 2026

Service providers

Cloudflare

Application hosting, structured database storage, private evidence-object storage, network delivery, and bot protection. Data may include account, workspace, learner, training, security-log, and generated evidence information. Vigil does not currently promise a specific data-residency region.

Resend

Transactional email delivery for platform invitations, administrative notices, and service messages. Data may include recipient name, email address, workspace name, delivery metadata, and message content.

Formspree

Public contact-form processing. Data is limited to the contact details, topic, organization, and message the visitor submits.

Google

Optional platform-user authentication and analytics on public marketing and legal pages. Sign-in data may include email address, display name, and stable account identifier. Public-site analytics may include page and device information and approximate location.

Customer-directed and independent services

These services are not used for every Vigil customer. A customer or platform user chooses whether to use or connect them, and each provider processes information under its own agreement or relationship with the customer.

Slack

Workspace identity, lesson delivery, responses, reminders, and application interactions. Slack remains the customer’s collaboration platform.

Paddle

Authorized reseller and merchant of record for self-service purchases. Paddle independently handles checkout, payment information, tax, invoicing, and buyer records.

Vanta and Drata

Optional destinations for customer-directed training-completion evidence. Vigil does not ingest broader business data from these platforms.

OpenAI and Anthropic

Optional bring-your-own-key AI providers. Only prompts and selected content submitted through an enabled AI feature are sent to the provider selected by the customer.

Changes and questions

Vigil may update this list when providers or processing purposes change. Material changes will be reflected in the revision date and communicated to customers when appropriate. Questions about a provider, transfer safeguard, or planned deployment can be sent to support@vigilsecurity.app.