Security
Security is not a checkbox. It's the product.
We hold ourselves to the same standards we help our customers achieve.
SOC 2 Type II
CERTIFIEDAudited annually by an independent CPA firm. Security, Availability, and Confidentiality trust service criteria.
Encryption at Rest
AES-256All customer data encrypted with AES-256. Database encryption keys rotated quarterly.
Encryption in Transit
TLS 1.3TLS 1.3 for all data in transit. TLS 1.0 and 1.1 disabled. Certificate transparency enforced.
Access Control
ZERO TRUSTMandatory MFA for all employees. Role-based access control. Privileged access reviewed quarterly.
Vulnerability Management
CONTINUOUSContinuous vulnerability scanning. Annual third-party penetration testing. Critical patches applied within 24 hours.
GDPR & CCPA
COMPLIANTData Processing Agreements available. Data residency options available for EU customers. DPO appointed.
Security Reports & DPA
SOC 2 Type II report, penetration test summary, and Data Processing Agreement available under NDA.
security@vigil.com →