Privacy Policy

Who Is Responsible

This website and the Vigilance product are operated by Modul4r Solutions (Marcello Delcaro), based in Alberta, Canada. Under the GDPR, Modul4r Solutions is the data controller for everything this page describes.

For any privacy question or request, email support@vigihq.com. A person reads it.

What the Software Sends

Pro sends nothing. It opens no network connection at all: no licence check, no heartbeat, no telemetry, no crash reports, no usage data, no files. Your licence is a signed file we email you, and the software never calls home to check it.

Free sends a report on every run. That is what the free tier costs, and it is the only reason it can be free. vigi activate registers the install and gets a key back. It sends hashes and capability data only. A name, an email or a file is sent only if you opt in, and each one needs its own yes. Every run after that posts one signed record to us. It carries the install id, the key, the time, and the Vigilance version. Then, for each file it read:

  • The sha256 of the file.
  • The file name, like index.js. Never the folder it sits in.
  • The capabilities found in it, like reaching the network or running a command.
  • Which of those capabilities are new since the version before.
  • Which of our own markers found each capability.
  • How many times each capability gets called.
  • Which third of the file each capability first appeared in.
  • A few structural words, like "text", "minified" or "signed".
  • For a compiled file, the names of its parts and how big each one is.

The record also carries this run's own verdict, and where the tool was blind. The blind spots are counts and file types only. They cover which formats it did not read, which files it did not fully parse, and a one-way hash of each unknown lump.

The report never sends a file path, an IP-linked identity, or anything about you. It sends a file, a name or an email only if you opt in, and each one needs its own yes.

A Free install that keeps itself up to date downloads our signed release list once a day, and the new version when there is one. That download carries nothing about the machine. Turn it off when you set up, or install through Homebrew, npm, pip, Scoop, apt or dnf, which update Vigilance themselves.

It feeds one thing: the capability registry. That registry tells us which of our own markers are worth keeping, and how often the tool raises an alarm nobody needed.

We use it for research into supply chain attacks, and to make the tool better. One day we can publish it or open it to others.

It is counts across many installs, never your install.

A machine with no network cannot run Free. Pro is the offline path.

This is one full report, exactly as it is sent. Nothing else leaves the machine.

one free-tier report
{
  "install_id": "b9f4c2a1-7e3d-4a56-9c21-0f8e2d5a1c77",
  "activated_key": "vgk_<the key vigi activate gave this install>",
  "time": "2026-08-25T05:12:03Z",
  "vigi_version": "0.2.0",
  "files": [
    {
      "hash": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855a",
      "name": "README.md",
      "powers": [],
      "heuristics": []
    },
    {
      "hash": "9f2b7c1d4e5a6f80c3b2a1908d7e6f5c4b3a29180716253d4c5b6a7f8e9d0c1b",
      "name": "postinstall.js",
      "powers": ["fetch", "shell-pipe"],
      "heuristics": ["minified", "base64"],
      "triggers": {
        "fetch": ["axios.get("],
        "shell-pipe": ["| sh"]
      },
      "combo": "fetch+shell-pipe",
      "gained": ["shell-pipe"],
      "counts": { "fetch": 6, "shell-pipe": 1 },
      "bands": { "fetch": "start", "shell-pipe": "end" },
      "sections": [
        { "name": ".text", "size": 81920 },
        { "name": "custom", "size": 4096 }
      ]
    }
  ],
  "run": {
    "verdict": "heads-up",
    "files_loud": 1,
    "files_total": 2,
    "compared": true
  },
  "coverage": {
    "unread_formats": { "ISO9660": 1 },
    "partial_failures": { "elf:imports": 1 },
    "bytes_scanned": 48213004,
    "bytes_skipped": 0,
    "members_unopened": 0,
    "unclassified": [
      {
        "ext": ".bin",
        "guess": "packed-or-encrypted",
        "missed": ["elf", "macho", "pe", "wasm", "java-class", "dex", "container-magic"],
        "hash": "7d9a1f4c2b3e5a6089c1d2e3f405162738495a6b7c8d9e0f1a2b3c4d5e6f7081"
      }
    ]
  },
  "sig": "<ed25519 signature over the report above>"
}

The first file is clean, so its capability list is empty. The second gained the capability to reach the network and pipe into a shell. Each file is a hash and its file name. There is no path and no content. The powers field is the capability list.

triggers and combo. The markers that found each capability, and the whole capability list written as one word. Both come from a fixed list we wrote. Neither is taken from your file. They tell us which markers turn up on ordinary software and which are rare.

gained, counts and bands. The gained list is the capabilities that file did not have in the version before. That is the only part of the report that says anything changed. The counts are numbers. The bands are one of three words, start, middle or end, and never a position.

sections. The shape of a compiled file: the name of each part and how big it is. Your compiler chose those names, not you.

We send a name only when it is on a list published in our source. If your build invented a name, we send the word “custom” instead, because a name your team chose belongs to you.

No content is sent, and no hash of any part.

run. This is whether this run raised an alarm. It also gives how many files it named, how many it read, and whether a previous version existed to compare against. We use it to measure how often the tool raises an alarm nobody needed, and to cut the rules that cause it.

The coverage block says where the tool did not see. It holds counts, file types, and one-way hashes only. It shows which formats had no reader, which files did not fully parse, and each unknown lump by shape. There is still no name, no path, and no content. The sample above shows every field it can carry.

trimmed. A very large scan can pass the size limit for one report. When that happens the report lists which of the fields above it dropped to fit, and nothing else. It is absent on a normal run.

What the Website Collects

Analytics and visitor identification. The website loads these third-party tools:

  • Google Analytics (Google). It sets cookies and records pages you visit, your rough location, your device, and how you found us. We use this to see what content works.
  • Warmly. It uses your IP address and cookies to match your visit to a company, and sometimes to a business profile. We use this to see which companies read the site.
  • Digital Pilot. Site analytics, similar to Google Analytics.
  • Microsoft Clarity (Microsoft). It records how you use a page, such as clicks and scrolling, so we can see what is hard to use.

Forms. If you send a contact, feedback or report form, we receive what you type. That is your email, your message, and the page you sent it from.

Freeform, our own form service, receives it. We use it to reply and, if you asked for updates, to send them. Every email we send has a working unsubscribe.

Purchases. Checkout runs on Stripe's own pages. Your card number goes to Stripe, never to us. We receive your email and the fact that you bought Pro, and we use them to email you the licence file. There is no machine id to collect. Stripe is the processor for payment data and has its own privacy policy.

The sandbox and hosting. The live sandbox and our host (Amazon Web Services) process your IP address to serve pages, cache results, and stop abuse with rate limits. The servers also write logs.

Why We Are Allowed to (Lawful Bases)

  • Contract: issuing your license, running the free tier you activated, and answering your messages (GDPR Art. 6(1)(b)).
  • Legitimate interest: keeping the site up, stopping abuse, and research into supply-chain attacks (Art. 6(1)(f)). The aggregate capability registry described above supports that research. The registry holds no personal data. It holds file hashes and counts across many installs. A fact only enters it once enough separate installs report the same file.
  • Consent: analytics and visitor-identification cookies (Art. 6(1)(a)). You can withdraw consent at any time. See Your rights below.

Who Processes It and Where

These companies process data for us:

  • Amazon Web Services: hosting, sandbox, free-tier activation records and scan reports, licence email, server logs.
  • Google: analytics, and the email you send to support@vigihq.com.
  • Stripe: payments.
  • Attio: contacts from earlier sign-ups.
  • Freeform: forms and licence email. Freeform is our own service and runs on Amazon.
  • Warmly: visitor analytics.
  • Digital Pilot: visitor analytics.
  • Microsoft: Clarity, page usage analytics.

Our own servers and storage run on Amazon in Canada. Most of the other companies are in the United States.

Transfers from the EU and UK rely on the EU–US Data Privacy Framework or Standard Contractual Clauses, depending on the provider. Canada holds an EU adequacy decision for data handled under PIPEDA.

We never sell anything that identifies you, your company, your code, or your machines. We never share any of it beyond the processors listed here.

The registry is the one exception, and it identifies nobody. It holds file hashes and the capabilities found in them, counted across every install and every package we scan ourselves.

A fact only enters it once enough separate installs report the same file. It is always a statement about software in the world, never about one machine.

We keep each install's own reports under its install id, apart from those counts. We never publish your install id, your run history or your own reports, and we never sell them.

How Long We Keep It

  • Contact entries: until you ask us to delete them.
  • Purchase records: 7 years, because tax law requires it.
  • Analytics data: up to 14 months, then Google deletes it.
  • Server and sandbox logs: kept in our Amazon account. They have no automatic delete date yet.
  • Free-tier scan reports: kept for as long as we run the registry. They are the registry, so deleting them deletes it. They hold file hashes and file names, no path and no file, and nothing in them identifies a person.
  • Activation records: kept while the install is active.

Your Rights (GDPR and UK GDPR)

If you are in the EU, EEA, or UK, you have rights over your data. You can ask us to:

  • Show it.
  • Correct it.
  • Delete it.
  • Hand it over in a portable format.
  • Restrict what we do with it.
  • Stop processing it.

You can withdraw any consent at any time. Email support@vigihq.com and we will answer within one month.

You can also complain to your local supervisory authority. The EDPB member list has every EU authority. In the UK it is the ICO.

Canadians hold similar rights under PIPEDA. Everyone else can email us too. We answer the same way, wherever you live.

Cookies

In the EU, the EEA, the UK and Switzerland, none of the tracking tools load until you press Accept on the cookie banner. In other countries they load when the page opens, with no banner. If you decline, here or on the banner, the site sets no tracking cookies at all and works exactly the same.

If you accept, the tools above set theirs: Google Analytics (_ga, _ga_*), Microsoft Clarity (_clck, _clsk) and the Warmly and Digital Pilot identifiers. Deleting cookies in your browser removes all of them.

Changes

If this policy changes, the new version appears here with a new date. We do not quietly widen what we collect.

Last updated: October 7, 2026.

Talk to Us

A privacy question or request? Send a note. It reaches a person.