Skip to content
Browse docs

Security

Continuous cloud security, not a once-a-year scramble. Vigil scans your environment every day, scores it, and tracks findings until they’re resolved.

What it is

Automated configuration and posture scanning against industry benchmarks, with a scored, de-duplicated findings database and advanced posture checks.

What you get

  • CIS scanning — daily critical checks plus a full scan every week
  • Security score (0–100) and severity breakdown
  • Findings database with auto-resolve when issues are fixed
  • Per-cloud frameworks:
    • AWS — Security Reference Architecture (SRA)
    • Azure — Microsoft Cloud Security Benchmark (MCSB)
    • GCP — CIS
    • DigitalOcean — CIS-lite
  • Automated threat modeling — refreshed on a regular cadence
  • Log analysis
  • SRA Verify — posture checks against AWS’s reference architecture

How to enable

Included in the Complete package, or available as an add-on. Requires a connected cloud account. Ask your Vigil team to enable it.

How to read it

  • Security score — a single number for posture at a glance; watch the trend, not just the value.
  • Findings — each has a severity and a status. Suppress or mark accepted risk for items you’ve reviewed and chosen to accept.
  • Auto-resolve — fixed issues clear themselves on the next scan, so the list reflects reality.

FAQ

What does Vigil scan against? CIS Foundations benchmarks and cloud-specific frameworks (SRA, MCSB, CIS), plus posture checks and threat modeling.

Does Vigil fix findings automatically? Findings are surfaced and prioritized. Remediation is done by your team, or by your Vigil engineers on a managed plan.

How often does it scan? Critical checks run daily; a full benchmark scan runs weekly.

Is there a one-time option? Yes — a one-time Security Audit delivers a full CIS assessment and roadmap. See Plans & modules.

Was this page helpful?

Your response helps us improve this page.