Vigil — security monitoring from the Praetorix family

Continuous security monitoring with evidence that holds up

Vigil collects and analyzes security events from your systems (SIEM), stores them in a cryptographically immutable audit trail and manages incidents within the NIS2 deadlines — 24 h / 72 h / 1 month. On top of that, a client compliance portal with a monthly report. Delivered as a managed service in the EU or on-premise in your own network.

Designed around frameworks and standards
NIS2 Art. 21 · 23 MITRE ATT&CK GDPR ISO 27001 EU SaaS · On-prem
<30 ms

Ingest latency under load

60-minute load test at 100 events per second: p95 server response 28.9 ms. Monitoring never slows your systems down.

24/24

Purple-team scenarios detected

Detection logic is continuously validated with simulated attacks — from password guessing through privilege escalation to bulk data exfiltration.

32 s

Recovery after failure (DR test)

Disaster-recovery drill over 662,000 events: operations restored within 32 seconds, with no loss of the audit trail.

Five pillars

One system from event collection to reporting to the regulator

Vigil covers the entire security operations lifecycle — it is not just a log collector, but a complete monitoring stack with evidentiary value.

Tamper-evident audit trail

Every event is hash-chained to the previous one and the chain is anchored outside the system (Merkle tree). Any later modification or deletion is mathematically provable — evidence for an auditor, a regulator and a court.

SIEM detection

Events from all sources in a unified schema (actor, action, resource, tenant, IP, outcome, severity). Correlation rules mapped to MITRE ATT&CK, with false-positive measurement and notification tiering.

Incidents within NIS2 deadlines

A critical event becomes an incident in a single step, with statutory reporting deadlines under Article 23 tracked automatically — early warning within 24 h, notification within 72 h, final report within 1 month.

Compliance under Article 21

Self-assessment of security measures, an asset and supplier register, evidence of baseline compliance (MFA, encryption, backups, patch management) — inspection-ready documentation, maintained continuously.

Integrations without rebuilds

Applications connect via SDK, HTTP API or syslog; existing logs (web server, auth log) via a log shipper mapping into the unified schema. A dropped-line counter guarantees nothing gets lost silently.

Prevention and active defense

Gateway and firewall orchestration: during an ongoing attack the system automatically tightens protection and relaxes it once the attack subsides. Scheduled vulnerability scans and a penetration test register are included.

Incident reporting

Who you report to, and within what deadlines

The Article 23 NIS2 deadlines are the same across all transpositions — what differs is the regulator, the reporting channel and the names of entity categories. Switch the legal framework to the country you operate in.

Legal frameworkSKCZPL
Regulatorthe competent national authority / CSIRT of the member state (national CSIRT)
Reporting channelthe competent national CSIRT
Legal basisDirective (EU) 2022/2555 (NIS2)
Implementing regulationsset by each member state's national transposition
Entity categoriesessential entity · important entity
Reporting deadlinesearly warning within 24 h · notification within 72 h · final report within 1 month

The reporting channel, the register and the exact deadlines are set by each member state's national transposition.

Features

What Vigil does — in detail

An overview of the system's functional areas. All security-relevant operations — including configuration changes to Vigil itself — are written to the same immutable audit trail.

AUDIT

Event hash chain

Append-only writes, every event cryptographically linked to the previous one; integrity verification with a single command.

AUDIT

Merkle anchoring

Periodic anchoring of the chain root outside the system — integrity remains provable even if the server is compromised.

AUDIT

Retention and WORM archive

Tiering: full-text searchable for 90 days, queryable up to 12 months (index reclaimed), immutable archive up to 24 months — each segment is sealed and its digest verified.

SIEM

Unified event schema

Normalization of all sources: timestamp, actor, action, resource, tenant, IP, outcome, severity. Versioned action dictionary.

SIEM

Detection rules

Declarative rules (YAML) mapped to MITRE ATT&CK: password guessing, permission changes outside working hours, bulk exports and deletions, DoS spikes.

SIEM

False-positive management

Mandatory alert closure (true / false / benign) and a continuous FP metric — monitoring that never cries wolf over time.

SIEM

Source watchdog

Ensures every connected system is actually sending events; a source going silent is an alert in itself.

NIS2

Article 23 incident workflow

Alert-to-incident escalation, tracking of the 24 h / 72 h / 1 month deadlines, documentation for CSIRT reporting.

NIS2

Article 21 self-assessment

Continuous assessment of measures — access management, MFA, encryption, backups, suppliers — with evidence from live operations.

PORTAL

Client portal

The customer sees their security posture, incidents, reports, invoices and contracts — strictly within their own tenant.

PORTAL

Monthly report (PDF)

Executive summary of events, alerts, incidents and compliance status; a snapshot of the figures is retained for audit.

PORTAL

DPA · SLA · billing

Data processing agreement and SLA generated from tenant data; DPA signature and plan changes are audit events in the hash chain.

GDPR

Identity pseudonymization

Identities in events protected with a per-tenant key (HMAC); crypto-shredding — destroying the key renders the data unreadable.

CORE

Multi-tenant isolation + RBAC

Strict customer separation with admin / operator / client roles; isolation verified by an automated cross-tenant pentest.

INTEG

SDK · HTTP · syslog · shipper

Drop-in SDK for applications, HTTP ingest, syslog; log shipper with mappers for existing logs without touching your systems.

DEFENSE

Active defense and pentests

Automatic gateway hardening during an attack with rollback once it subsides; orchestration of vulnerability scans and purple-team scenarios.

Quality assurance

A monitoring system that is itself under watch

A security tool must withstand stricter criteria than the systems it protects. Vigil is therefore continuously tested with load, simulated attacks and disaster recovery — and it monitors itself.

245 automated tests in CI

Every code change passes the full test suite — from chain integrity through detection rules to tenant isolation.

Purple-team harness — 24 attack scenarios

Simulated attacks run against an isolated instance and verify that the detections actually catch what they are supposed to catch.

Load and disaster-recovery testing

60 minutes at 100 events/s with a p95 response of 28.9 ms; disaster recovery over 662,000 events within 32 seconds with no loss of the trail.

Tenant isolation pentest

Automated attempts to access another tenant end in denial — isolation is not a claim, it is tested.

Dogfooding — Vigil watches Vigil

The system logs its own logins, configuration changes and administrative actions into the same immutable trail it provides to customers.

Deployment

From the first source to full monitoring in three steps

Onboarding is designed to require no rebuild of your systems — we connect to what you already log and add depth incrementally.

Connection and trial

We set up your tenant and connect the first event source — typically within 2 hours. During the 30-day trial you see your own data in your own dashboard, with no commitment.

Implementation

We connect the agreed systems (SDK, HTTP, syslog, log shipper), tune detections to your operations, populate the asset and supplier register and sign the DPA + SLA. We train your people.

Operations and monitoring

Continuous collection and detection, incidents handled within statutory deadlines, a monthly executive report and documentation kept ready at all times for an audit or a regulator's inspection.

Pricing

Transparent plans by organization size

Monthly subscription with no hidden items. Prices are final — we are not VAT registered; valid from August 1, 2026. A one-off implementation fee is added to the plan based on the size of the environment.

Monthly plans

Trial

30-day evaluation — your own data in your own dashboard
€0 / 30 days
no SLA · no commitment
  • Full system functionality
  • 1 event source, 5 devices
  • 1-month retention
  • Connected within 2 hours
Try it

Start

Small business or municipality of up to 5,000 residents
€149 / mo
SLA bronze · e-mail, business days
  • 3 sources, 25 devices
  • Core detections: logins, brute-force attacks, permission changes
  • Tamper-evident audit
  • Monthly report · 6-month retention
I'm interested
For NIS2 entities

Standard

City, hospital or mid-sized company under NIS2
€390 / mo
SLA standard · 8×5, 4 h response
  • 10 sources, 100 devices
  • Everything in Start + NIS2 module
  • Asset and supplier register
  • Incidents with 24 h / 72 h / 1 month deadlines
  • Article 21 self-assessment · 12-month retention
I'm interested

Enterprise

Critical infrastructure, multiple sites
€890 / mo
SLA gold · 24×7, 1 h response
  • Unlimited sources and devices
  • Active gateway defense
  • Penetration test orchestration
  • Dedicated instance · 24-month retention
I'm interested

On-prem license — data never leaves your network

Vigil runs on your infrastructure. The price includes the license, updates and support; we deliver installation, a runbook and administrator training, while you operate the server and handle backups yourself. Suitable for organizations with strict data sovereignty requirements.

Full NIS2 moduleActive defenseUnlimited devicesSLA standard
License + support
€1,000 / mo
billed monthly · €12,000/year · final price Discuss deployment

One-off implementation

Start

€2,900 one-off
~16 h of work · delivery within 10 days

1 site, up to 25 devices, 3 log sources. Installation, source onboarding, core detections tailored to the environment, 4 hours of training, handover protocol.

Standard

€6,900 one-off
~48 h of work · delivery within 21 days

Up to 100 devices, 10 sources, the NIS2 module including a populated asset and supplier register, integration of 2 of your own applications, detection tuning, 8 hours of training.

Enterprise

€14,900 one-off
~120 h of work · delivery within 45 days

Multiple sites, over 100 devices, custom integrations, migration from an existing SIEM, active gateway defense, documentation for audits and regulator inspections.

Additional services

NIS2 entry audit and gap analysis

Environment review, comparison against the law and Article 21; the deliverable is a findings report and a prioritized action plan.

€1,900one-off

Penetration test of a website or application

Automated scan with manual verification of findings; a report with evidence and recommendations, retest after remediation.

from €2,400per target

Purple team exercise

A simulated attack against an agreed scenario, verifying whether monitoring catches it and whether people respond correctly.

€1,800one-off

Incident standby

Guaranteed intervention by a security specialist during an incident, including help with reporting within the Article 23 deadlines.

€350per month

Connecting an additional system

A log source or application beyond the plan's scope — via SDK, HTTP interface or syslog.

€480per system

Employee training

Security awareness and hands-on system operation, on site or online.

€690per day

Representation during a regulator's inspection

Preparation of documentation and participation in the inspection or in resolving an incident report.

€120per hour

Custom requirements

Custom integrations, specific reports or detections — we will be glad to prepare a quote.

on request 

Commercial policy: 15% discount for two years paid in advance · 30% for non-profits and schools · 40% for the first customer in a segment in exchange for a reference · monthly payment without an annual contract +20%. Partner program for integrators: 15% commission on implementation and 10% on operations.

FAQ

Frequently asked questions

How does Vigil relate to Praetorix?+

Praetorix is a GRC tool for compliance management — asset inventory, risk analysis, SoA and audit deliverables. Vigil is its operational twin: continuous security monitoring — event collection and detection (SIEM), an immutable audit trail and incident management within NIS2 deadlines. Together they cover both governance and operations; each can also be deployed on its own.

What does a "tamper-evident" audit trail mean?+

Every event is cryptographically chained to the previous one (hash chain) and the chain is periodically anchored outside the system (Merkle tree). Any later modification or deletion of any event is mathematically provable. The audit trail therefore serves not only operations, but as evidence before an auditor, a regulator and in potential litigation.

Does Vigil cover NIS2 obligations?+

Yes — the technical measures of Article 21 (monitoring, logging, access management, continuity), including self-assessment and inspection-ready documentation, and the Article 23 incident reporting process with deadline tracking: early warning within 24 hours, notification within 72 hours and a final report within 1 month. The Standard plan is designed precisely for entities falling under NIS2.

Does Vigil run in the cloud or on-premise?+

Both. Standard plans run as a managed service on EU infrastructure. The On-prem plan runs Vigil on the customer's infrastructure — data never leaves their network; we deliver installation, updates, a runbook and administrator training.

What about personal data protection (GDPR)?+

Identities in events are pseudonymized with a key bound to the specific customer (HMAC), and when the legal basis expires, crypto-shredding is applied — destroying the key renders historical data permanently unreadable. Onboarding includes a data processing agreement (DPA); its signature is itself recorded as an event in the audit chain.

How quickly can Vigil be deployed?+

A trial tenant with its first event source is connected within 2 hours. The Start implementation takes approximately 10 calendar days, Standard 21 days and Enterprise 45 days — calendar time includes the customer's own cooperation (access, approvals); our actual work amounts to 16 to 120 hours depending on scope.

No-obligation request

Request a Vigil demo

Fill in the form — we will create a tracked ticket and get back to you within 24 hours with a proposed demo date. A trial tenant with your first event source can be connected within 2 hours.

  • No obligation, no cost
  • A tracked ticket with a reference number
  • A demo on your own data
  • 30-day trial with full functionality

New ticket — Vigil

PRX-DEMO-••••

Submitting creates a tracked ticket. We will get back to you within 24 hours.

Get monitoring that stands up to the regulator

Write to us or request an access ticket — within 24 hours we will get back to you with a proposed date for a demo on your own data.