Catch Supply Chain Attacks, Not False Alarms.
Vigilance compares what you run with the update about to replace it. It shows only the files that gained a new capability, like reaching the internet or reading your keys.
One file. No agent. Mac, Linux, Windows and the BSDs.
Over 70% of software supply chain attacks do not use known CVEs whatsoever.
We can catch the next NotPetya, SolarWinds, Kaseya, or 3CX before any damage is done. No one else can.
Watch It Work
Real supply chain attacks, replayed in your browser. The first is @apexacc/cli, a live npm backdoor Vigilance caught the day it shipped. Pick one and read what Vigilance says.
loading…
How It Works
Three steps.
-
Point It at a Folder
The folder can hold an installed program, a container image, a package or a build output. The first run records every file, and what each file can do.
-
Take the Update
Run Vigilance again. It compares the new files against the first run.
-
Read the One Line
It shows every file that gained a capability. Most days it shows nothing.
One file to install, and nothing to configure. It runs on Mac, Linux, Windows and the BSDs. It reads inside deb, rpm, npm, pip, containers, MSI, ISO and more. It never blocks a program. It never sends your code anywhere. Pro opens no connection at all.
Who This Is For
Anyone who installs software they did not write.
You look after a fleet
One line enrols a machine. No agent, no console, one page for all of it.
You run an AI coding agent
It installs faster than you can read. This reads each one for you.
Your team takes updates
It stays quiet on the normal changes and shows the one file that matters.
You ship your own builds
It shows the file your build produced that none of your inputs explain.
Pricing
Flat per company. No per-endpoint pricing. The price steps on how big you are, never on how many machines you count.
Prices are Canadian dollars. You are charged in your own currency at checkout.
For solo devs, agents, and small businesses
Free Forever
$0/mth
Needs a network
- Full scanner
- Up to 50 machines
- Sends telemetry (what that means)
- Support queue
For the whole company
Pro
$999/mth
$9,990/yr2 months free
$2,999/mth
$29,990/yr2 months free
$9,999/mth
$99,990/yr2 months free
Let’s talk
Let’s talk
for up to 500 machines
Works offline
- No phone home: no network, no telemetry
- Fleet management
- More than 50 machines
- Same scanner as Free
- Flat for the whole company
- Priority support
Are you an MSP? Talk to us
OEM / Vendor
Let’s talkShip it inside your product
Put Vigilance in what you sell
- Embed the engine
- Air-gapped
- White-label
- Signed licence
The same check runs on every one. Vigilance catches files that gain new capabilities they didn't have before.
FAQ
How is this different from antivirus?
Antivirus finds files it already knows are bad. Vigilance finds new behaviour in an update that looks clean.
Is this file integrity monitoring?
It does that job and one more. A file integrity checker tells you a file changed. Vigilance tells you what the change lets that file do. See file integrity monitoring, or FIM for Windows.
Will it flood me with alerts?
Most days it reports nothing. A normal update changes files but gains no new capability, so it stays quiet. It speaks up only when a file can suddenly do more.
How do you tune it?
We scan new software as it ships and tune the checks with what we learn. The goal is fewer false positives. There is no CVE list or threat feed behind it. A program can only be written in so many ways to reach the internet, run a command, or read your keys. We read for those.
How do you know how many machines I have?
We do not meter it. A Pro build has no network code in it at all, so it
cannot tell us. You tell us once a year. Run
vigi fleet count on your manager machine. It reads the number
out of your own fleet folder, signs it with your key, and gives you one block to
send. The number never blocks a machine. If a company grows past its band
mid-year, it keeps scanning everywhere. We sort it out at renewal.
What if I am just over a band?
You stay where you are. Up to ten percent over your band renews on your current band, so 540 machines is still band S. Past that, the next band applies at your next renewal. We count machines that are running Vigilance on renewal day, so a decommissioned VM is not something to argue about.
What currency are these prices?
Canadian dollars. We are a Canadian company. The same numbers are also set in US dollars, so a US buyer pays $999 USD and a Canadian buyer pays $999 CAD. Checkout picks your currency for you. Nobody has to convert anything. Prices exclude tax. Checkout adds sales tax where the law requires it.
Does it send my files anywhere?
Never your files. Pro opens no connection at all. Free posts a signed report of each file hash, its name, and the capabilities found in it. Never your code, and never the folder a file sits in. See a full report.
Does it need the internet?
Pro does not. It works fully offline, even air-gapped. Free needs the internet to run.
Can it look inside packages and archives?
Yes. It reads inside deb, rpm and npm packages, and inside xz, zstd, lz4, 7z, MSI, CAB, xar, ISO and squashfs. Each reader is hand-written with no dependency. A format it cannot open yet becomes a loud finding, never a quiet pass.
Is it open source?
No. The people who poison updates work behind closed doors, so we do too. Published checks are checks an attacker can read and dodge. What we can open is on the Verify page: every download is signed, and you can check yours before you run it.