Security you can inspect.
How Vigilante protects the commands, the data and the people who use it.
Controls
-
Signed commands
Ed25519 signatures, a ten-minute validity window, replay protection, and binding to one device and one tenant. Without a key, the system refuses to act.
-
Signed updates
The agent verifies an Ed25519 manifest signature and a SHA-256 hash before an update runs.
-
Device identity
Each device holds a short-lived token protected with Windows DPAPI, renewed automatically.
-
Tenant isolation
The tenant comes from the signed-in identity, never from the request, and API queries are filtered by it.
-
Encryption of sensitive data
Quarantined files, BitLocker recovery keys and connector credentials are encrypted with AES-256-GCM.
-
Audit log
HMAC-chained, verifiable and exportable with a signature. Kept for three years by default.
-
Access control
Fine-grained roles, time-limited delegation across tenants, and one-time-password step-up on sensitive actions.
-
Agent self-protection
The agent hardens its files and service, restarts after failure, and raises an alert when its binaries or configuration change.
-
Hardened deployment
Container images are pinned by digest, production Helm values run pods as non-root with a read-only filesystem, and dependencies are scanned for known vulnerabilities on a schedule.
What leaves the endpoint.
Defaults are configurable per deployment.
| Data | What it is | Retention or trigger |
|---|---|---|
| Telemetry events | Process, network, file, registry and DNS activity from the agent. | 90 days by default |
| Alerts and threats | Correlated alerts and the threat records behind them. | 1 year by default |
| Audit and response log | Who did what, and every command sent to an endpoint. | 3 years by default |
| Forensic triage packs | Registry, event logs and other artifacts. | Only on operator command |
| BitLocker recovery keys | Escrowed in encrypted form. | Only if you enable escrow |
| AI triage (optional) | When enabled, alert context including command lines and file paths is sent to the configured model provider. | Only if you enable it |
Good to know
A local administrator can stop the agent service. Kernel-level tamper protection is not part of the current release.
Vigilante supports your own GDPR and NIS2 duties with logs and evidence. It does not make an organization compliant on its own.
A clearer next move.
See how Vigilante fits your endpoints and your team.