Contextual intelligence for risks beyond the perimeter.
Vigil correlates credential exposure, underground activity, phishing infrastructure and externally observable technology risk with the domains, identities, brands and third parties relevant to your organisation. Deploy it as an on-premises appliance or use it as a managed SaaS service.

Seven intelligence modules. One correlation engine.
Each module addresses a distinct external-risk domain while using a shared correlation, investigation and reporting workflow.
Credential Intelligence
Stealer logs, combolists and breach dumps matched to authorised identities, with exposure relationships and a timeline.
ExploreDark Web & Underground
Selected forums, marketplaces, lawfully accessible messaging communities and ransomware leak sites monitored for relevant organisational references.
ExplorePhishing & Brand
Look-alike domains, phishing infrastructure and fake pages — with evidence to support investigation and abuse reporting.
ExploreExternal Risk Assessment
Structured checks across authorised domains, with evidence-backed findings, relevant MITRE ATT&CK references and prioritised remediation guidance.
ExploreSupply Chain & VIP
Vendor breach records, ransomware victim lists, mentions of your suppliers in monitored underground sources and executive exposure provide current evidence for third-party review.
ExploreVulnerability Intelligence & Response Workflows
Vulnerability records with KEV context are matched to observed technologies; supported workflows route findings to SIEM, SOAR, Jira or Teams.
ExploreMalware & Payment Security
Suspicious files are read and checked against YARA rules on your instance, never executed or retained; merchant, terminal and BIN identifiers are watched across monitored sources.
ExploreFrom external signal to prioritised security action.
A unified workspace for monitoring, investigation, evidence review and reporting. Analyst-level evidence and executive-level reporting are produced from the same underlying findings.
A structured assessment of externally observable risk.
Vigil evaluates a customer-authorised domain through phased discovery and intelligence checks. Results are normalised, correlated and prioritised to support technical remediation and management reporting.
- 01DiscoverAssets and attack surface
- 02CorrelateLeak, brand and threat data
- 03PrioritiseCVE, MITRE ATT&CK, attack paths
- 04ActRisk score, plan and report

Alerts, response and reporting on the same platform.
A finding is not the end of the work. Vigil carries it through notification, takedown, prioritisation and the report your management or auditor will read.
Alerts you configure
For each category you set whether it notifies, the minimum severity and the e-mail preference. Critical and high findings appear in the in-product alert stream; the monitor checks new records every 30 seconds.
Response and takedown
Takedown Center keeps the case, the notice, the reply and the evidence in one process. Notices are sent from your own SMTP server; a notice counts as sent only when the mail server accepts it. Removal remains the provider’s decision.
Reports for each audience
Executive, technical, compliance, VIP, vendor and brand reports are produced as PDF in Turkish and English. Delivery by download, e-mail or schedule; each report fixes its period so the next one can be compared against it.
Supply-chain monitoring
Add a supplier by name and domain. The monitor compares against the previous state every 30 minutes and routes new changes and new exposure to the related alert category.
Vulnerability prioritisation
A vulnerability is assessed by its technical score together with exploitation likelihood, active exploitation in the CISA catalogue and whether a public exploit exists. Records that name a monitored supplier enter the alert stream.
Threat graph and regional context
The threat graph links credentials, leaks, actors, domains, IOCs and campaigns so a finding can be followed to its relationships. Regional modules follow national sources and the groups active in each region.
A deployment model designed for operational control.
In an on-premises deployment, curated intelligence is synchronised to the customer appliance through a documented channel. Matching against monitored assets and identities occurs within the customer-controlled environment.
Integrate external intelligence into existing security operations.
Deliver validated findings and alerts to SIEM, SOAR, case-management and collaboration platforms through supported connectors, webhooks and REST APIs. Vigil complements existing SOC processes without requiring analysts to replace their primary operational tools.
Product overview and review materials.
Vigil brochure
Reviewed product overview for security, risk and procurement teams — PDF.
OpenArchitecture and data-flow review
Deployment, connectivity, data location, access control and retention are reviewed against the customer environment.
OpenIntegration and API scope
Supported integrations and API functions are confirmed for the selected licence and order form.
OpenQuestions buyers ask before a demo.
What sources does Vigil monitor?+
Vigil monitors selected underground forums and marketplaces, lawfully accessible messaging communities, stealer log collections, breach datasets, paste services, exposed code repositories, phishing and certificate-transparency sources, ransomware leak sites and vulnerability intelligence. Coverage changes as sources become available, relevant or inaccessible.
How fast are we alerted?+
Collection and matching are continuous. Depending on source availability and processing status, high-priority alerts can be generated within minutes of ingestion and routed according to customer-defined rules.
Does Vigil replace our SOC?+
No. Vigil is the external intelligence and exposure layer. Your SOC continues to monitor internal telemetry; Vigil routes relevant externally observed findings into the tools your SOC already uses.
Where is customer data stored?+
For on-premises deployments, monitored assets, findings and user activity are stored in a customer-isolated database within the customer-controlled environment. Connectivity and data-flow requirements are documented during security review. SaaS data-location and retention requirements are agreed during scoping.
How long does deployment take?+
A standard on-premises implementation is generally completed within four weeks, subject to infrastructure readiness, security approvals and integration scope.
How is it licensed?+
Vigil is licensed per organisation in three tiers. Monitored scope, users, scans, reports, deployment model and Enterprise limits are confirmed in the applicable quote and order form.
Evaluate Vigil against your external risk profile.
Review the platform, an anonymised assessment report and the deployment model with a GNSAC security specialist.








