Trust & security
Vigil is built so you never have to trade security for visibility. Here’s exactly how your access and data are handled.
The agent runs in your account
For AWS, Azure, and GCP, the Vigil agent is deployed inside your own cloud account. Your raw infrastructure data originates and stays in your tenant. Vigil connects to it — it doesn’t relocate your environment into ours.
Keyless, least-privilege access
Vigil never asks you to create or share long-lived access keys:
| Provider | Access method |
|---|---|
| AWS | An IAM role Vigil assumes (created by the CloudFormation stack) |
| Azure | A user-assigned managed identity |
| GCP | A keyless attached service account |
| DigitalOcean | A read-scoped API token you control and can revoke |
| Microsoft 365 / Google Workspace | Admin-consented, read-scoped app access |
The permissions requested are read, inventory, security-review, and cost — not write access to your workloads. Vigil surfaces and prioritizes issues; it doesn’t make changes to your infrastructure unless you’re on a managed plan and have explicitly authorized remediation work.
Your data is isolated
- Metrics are stored in an isolated, per-customer tenant — your data is never mixed with another customer’s.
- Findings, cost data, and evidence are stored per-organization with role-based access, so your team only sees what they’re entitled to.
Data retention
Metric retention follows your plan tier:
| Tier | Retention |
|---|---|
| Starter | 7 days |
| Professional | 30 days |
| Enterprise | 90 days |
Revoking access
You can revoke Vigil’s access at any time by removing the deployed stack/identity or the API token in your own account — access ends immediately.
Questions?
For a security review, DPA, or vendor-assessment questionnaire, contact support@vigilcloud.io and your Vigil team will help.