VIGIL Public Documentation
ESControl Plane

SOVEREIGN SECURITY OPERATIONS

Security operations

Understand ingestion, correlation, incidents and customer-controlled policy at a safe public level.

Ingestion and correlation

Vigil receives authorized summaries from connected tools and correlates activity across email, identity, endpoint, network, vulnerability, session and AI domains.

Incidents

A single operational incident records what happened, why the activity matters, the applicable policy, the response decision and the resulting evidence.

Customer policy

Vigil Standard Policies and customer policies define protected assets and identities, allowlists, denylists, confidence and severity boundaries, approved actions and verification requirements. Vigil may automate execution. The customer defines the boundary.