Customer-controlled threat intelligence deployment.
For organisations with demanding data-governance and supplier-assurance requirements, Vigil can run as an OVF/OVA appliance in the customer-controlled environment with a customer-isolated database and documented connectivity.

Deployment considerations for regulated environments
Watchlists and findings may be sensitive
Domains, executive names, supplier lists and findings may require customer-controlled storage, access controls and documented data flows.
Data location and supplier assurance
Regulated organisations commonly need clear answers on data location, tenant isolation, administrative access, retention and cross-border transfers.
Restricted and segmented networks
OT and restricted zones may impose tightly controlled connectivity requirements that must be addressed during architecture review.
How Vigil is deployed
An appliance in your virtualisation environment, a documented intelligence synchronisation channel and integrations with the tools you already use.
- 01 · Install
OVF/OVA in your environment
Deployed into the customer virtualisation environment with a customer-isolated database, two-factor authentication, role-based access and auditable activity records.
- 02 · Synchronise
Intelligence through CentralSync
Curated external intelligence is delivered to the customer instance through a documented channel. Customer data flows and connectivity requirements are reviewed during implementation.
- 03 · Integrate
SIEM · SOAR · Jira · ServiceNow · Teams
Supported alerts, response workflows and reports can be routed into existing tools through the REST API and available connectors.
- 04 · Operate
Transition to operational use
Tuning, training, reporting and handover are completed against the agreed implementation plan. A typical four-week schedule remains subject to scope, readiness and security approvals.

Risk score, exposure summary, threat-actor activity, threat-activity overview and credential exposure — served from the customer appliance.
What changes for your team
Documented deployment controls
Data location, isolation, access control, connectivity and activity records can be evidenced through the deployment design and supporting documentation.
Options for restricted environments
Segmented and restricted-network requirements are reviewed during scoping to determine a suitable connectivity and update model.
Licensed per organisation
Tiers are defined by monitored domains, users, scans and reports — the SOC, the fraud team and management work from the same findings.
Questions we get asked
How does intelligence synchronisation work?+
Curated external intelligence is synchronised to the customer appliance through a documented channel. Matching against monitored customer assets occurs locally; all connectivity and data flows are confirmed during security review.
Can it run in a restricted network?+
The appliance operates inside your network and needs only a controlled, outbound-initiated channel (CentralSync) for intelligence updates. Requirements for restricted or segmented networks are reviewed during scoping.
Who has access to our instance?+
Your administrators, under role-based access control. Any support access is granted by your administrators and recorded in the audit trail.
Review the deployment model with an engineer.
A focused technical session covering architecture, connectivity, integration points and an implementation plan for your environment.
