Catch Supply Chain Attacks, Not False Alarms.

Vigilance compares what you run with the update about to replace it. It shows only the files that gained a new capability, like reaching the internet or reading your keys.

Start Free See Pricing

One file. No agent. Mac, Linux, Windows and the BSDs.

Over 70% of software supply chain attacks do not use known CVEs whatsoever.
We can catch the next NotPetya, SolarWinds, Kaseya, or 3CX before any damage is done. No one else can.

Watch It Work

Real supply chain attacks, replayed in your browser. The first is @apexacc/cli, a live npm backdoor Vigilance caught the day it shipped. Pick one and read what Vigilance says.

loading…
loading…

Explore the attack case studies

What does a compromised update cost?

How It Works

Three steps.

  1. Point It at a Folder

    The folder can hold an installed program, a container image, a package or a build output. The first run records every file, and what each file can do.

  2. Take the Update

    Run Vigilance again. It compares the new files against the first run.

  3. Read the One Line

    It shows every file that gained a capability. Most days it shows nothing.

One file to install, and nothing to configure. It runs on Mac, Linux, Windows and the BSDs. It reads inside deb, rpm, npm, pip, containers, MSI, ISO and more. It never blocks a program. It never sends your code anywhere. Pro opens no connection at all.

Pricing

Flat per company. No per-endpoint pricing. The price steps on how big you are, never on how many machines you count.

Prices are Canadian dollars. You are charged in your own currency at checkout.

For solo devs, agents, and small businesses

Free Forever

$0/mth

Needs a network

  • Full scanner
  • Up to 50 machines
  • Sends telemetry (what that means)
  • Support queue
Start Free

OEM / Vendor

Let’s talkShip it inside your product

Put Vigilance in what you sell

  • Embed the engine
  • Air-gapped
  • White-label
  • Signed licence
Talk to Us

Vigilance for MSPs

Run Vigilance on every client you manage. Tell us a little about your clients and we will send the MSP plan.

Dev computers End-user machines Edge devices Air-gapped Coding agents CI runners

The same check runs on every one. Vigilance catches files that gain new capabilities they didn't have before.

FAQ

How is this different from antivirus?

Antivirus finds files it already knows are bad. Vigilance finds new behaviour in an update that looks clean.

Is this file integrity monitoring?

It does that job and one more. A file integrity checker tells you a file changed. Vigilance tells you what the change lets that file do. See file integrity monitoring, or FIM for Windows.

Will it flood me with alerts?

Most days it reports nothing. A normal update changes files but gains no new capability, so it stays quiet. It speaks up only when a file can suddenly do more.

How do you tune it?

We scan new software as it ships and tune the checks with what we learn. The goal is fewer false positives. There is no CVE list or threat feed behind it. A program can only be written in so many ways to reach the internet, run a command, or read your keys. We read for those.

How do you know how many machines I have?

We do not meter it. A Pro build has no network code in it at all, so it cannot tell us. You tell us once a year. Run vigi fleet count on your manager machine. It reads the number out of your own fleet folder, signs it with your key, and gives you one block to send. The number never blocks a machine. If a company grows past its band mid-year, it keeps scanning everywhere. We sort it out at renewal.

What if I am just over a band?

You stay where you are. Up to ten percent over your band renews on your current band, so 540 machines is still band S. Past that, the next band applies at your next renewal. We count machines that are running Vigilance on renewal day, so a decommissioned VM is not something to argue about.

What currency are these prices?

Canadian dollars. We are a Canadian company. The same numbers are also set in US dollars, so a US buyer pays $999 USD and a Canadian buyer pays $999 CAD. Checkout picks your currency for you. Nobody has to convert anything. Prices exclude tax. Checkout adds sales tax where the law requires it.

Does it send my files anywhere?

Never your files. Pro opens no connection at all. Free posts a signed report of each file hash, its name, and the capabilities found in it. Never your code, and never the folder a file sits in. See a full report.

Does it need the internet?

Pro does not. It works fully offline, even air-gapped. Free needs the internet to run.

Can it look inside packages and archives?

Yes. It reads inside deb, rpm and npm packages, and inside xz, zstd, lz4, 7z, MSI, CAB, xar, ISO and squashfs. Each reader is hand-written with no dependency. A format it cannot open yet becomes a loud finding, never a quiet pass.

Is it open source?

No. The people who poison updates work behind closed doors, so we do too. Published checks are checks an attacker can read and dodge. What we can open is on the Verify page: every download is signed, and you can check yours before you run it.