External intelligence.On your terms.
GNSAC Vigil correlates credential exposure, underground activity, phishing infrastructure and external risk with the assets, identities and third parties relevant to your organisation. Deploy on-premises or use Vigil as a managed SaaS service.
From external signal to prioritised security action.
A unified workspace for monitoring, investigation, evidence review and reporting. Analyst-level evidence and executive-level reporting are produced from the same underlying findings.
Four intelligence domains. One organisational risk context.
Vigil brings together credential exposure, underground activity, phishing and brand abuse, and externally observable technology risk. Findings retain source context and are correlated with the entities relevant to the customer.
Credential Intelligence
- Stealer logs, combo lists, breach dumps
- Privileged account exposures
- Exposure relationships and source chain
Dark Web & Underground Channels
- Selected dark web forums and marketplaces
- Lawfully accessible messaging communities under continuous monitoring
- Threat-actor discussions, paste services and leak sources
Phishing & Brand Protection
- Typosquat domains and fake sites
- CT-log and 3.1M phishing URL repository
- Social media and mobile app impersonation
External Exposure & Supply Chain
- External assets and CVE matching
- Vendor breaches, ransomware victim lists
- Third-party risk scoring
A structured assessment of externally observable risk.
Vigil evaluates a customer-authorised domain through phased discovery and intelligence checks. Results are normalised, correlated and prioritised to support technical remediation and management reporting.

Technical Assessment Report
Evidence-backed findings · affected assets · source context · relevant MITRE ATT&CK references · prioritised remediation guidance
Executive Risk Brief
Material exposures · business relevance · ownership · recommended management actions
Deployment options aligned to your security model.
Vigil is available as an on-premises virtual appliance or a managed SaaS service. On-premises deployments keep customer findings, monitored assets and user activity within the customer-controlled environment. Detailed architecture, connectivity and data-flow documentation is available for security and supplier-assurance review.
Deployed in operationally sensitive environments.
Vigil supports security operations in maritime services, manufacturing, infrastructure services and cybersecurity. Anonymised deployment profiles and customer reference discussions are available for qualified evaluations, subject to customer approval.
Integrate external intelligence into existing security operations.
Deliver validated findings and alerts to SIEM, SOAR, case-management and collaboration platforms through supported connectors, webhooks and REST APIs. Vigil complements existing SOC processes without requiring analysts to replace their primary operational tools.
Engineering notes from the team that builds Vigil.
What I Learned Scaling a Credential Exposure Engine to 3.8 Billion Records
Storage layout, indexing and query design behind Vigil’s credential intelligence.
Building a Multi-Channel Phishing Simulation Platform in Go for Regulated Industries
Architecture of GNSAC Phishing for teams that must run it on-prem.
exposure-check — open-source exposure scanner
What attackers can see about your GitHub orgs, repos and domains. MIT, Go.
Product engineering and security expertise, delivered together.
Vigil is developed and supported by GNSAC. Customers can retain operational control through an on-premises deployment or select a managed SaaS service.
Customer-controlled deployment
The on-premises appliance uses a customer-isolated database and a documented intelligence synchronisation channel. Detailed data flows are available for security review.
Operational intelligence at scale
Vigil continuously processes collected exposure and threat data. Platform metrics are reported with their scope and processing status to support informed evaluation.
Organisationally relevant findings
Signals are correlated with authorised domains, identities, brands and third parties, then retained with source context for investigation.
Specialist implementation and support
GNSAC security engineers support deployment, integration and tuning through defined support channels and escalation paths.
Questions enterprise security teams ask.
Does Vigil replace our SOC / CSIRT?+
No. Vigil is the external threat-intelligence and exposure-management layer. Your SOC keeps watching logs and events inside the network; Vigil detects signals outside and delivers them into the tools your SOC already runs.
Where is customer data stored?+
In an on-premises deployment, findings, monitored assets and user activity are held in a customer-isolated database within the customer-controlled environment. Connectivity and data-flow requirements are documented during security review. SaaS data-location and retention requirements are agreed during scoping.
How long does deployment take?+
A standard on-premises implementation is generally completed within four weeks, subject to infrastructure readiness, security approvals and integration scope. The implementation plan covers deployment, integrations, tuning, training and transition to operational use.
Evaluate Vigil against your external risk profile.
Request a product demonstration, review an anonymised assessment report, or discuss deployment and integration requirements with a GNSAC security specialist.

