Continuous security monitoring with evidence that holds up
Vigil collects and analyzes security events from your systems (SIEM), stores them in a cryptographically immutable audit trail and manages incidents within the NIS2 deadlines — 24 h / 72 h / 1 month. On top of that, a client compliance portal with a monthly report. Delivered as a managed service in the EU or on-premise in your own network.
Ingest latency under load
60-minute load test at 100 events per second: p95 server response 28.9 ms. Monitoring never slows your systems down.
Purple-team scenarios detected
Detection logic is continuously validated with simulated attacks — from password guessing through privilege escalation to bulk data exfiltration.
Recovery after failure (DR test)
Disaster-recovery drill over 662,000 events: operations restored within 32 seconds, with no loss of the audit trail.
One system from event collection to reporting to the regulator
Vigil covers the entire security operations lifecycle — it is not just a log collector, but a complete monitoring stack with evidentiary value.
Tamper-evident audit trail
Every event is hash-chained to the previous one and the chain is anchored outside the system (Merkle tree). Any later modification or deletion is mathematically provable — evidence for an auditor, a regulator and a court.
SIEM detection
Events from all sources in a unified schema (actor, action, resource, tenant, IP, outcome, severity). Correlation rules mapped to MITRE ATT&CK, with false-positive measurement and notification tiering.
Incidents within NIS2 deadlines
A critical event becomes an incident in a single step, with statutory reporting deadlines under Article 23 tracked automatically — early warning within 24 h, notification within 72 h, final report within 1 month.
Compliance under Article 21
Self-assessment of security measures, an asset and supplier register, evidence of baseline compliance (MFA, encryption, backups, patch management) — inspection-ready documentation, maintained continuously.
Integrations without rebuilds
Applications connect via SDK, HTTP API or syslog; existing logs (web server, auth log) via a log shipper mapping into the unified schema. A dropped-line counter guarantees nothing gets lost silently.
Prevention and active defense
Gateway and firewall orchestration: during an ongoing attack the system automatically tightens protection and relaxes it once the attack subsides. Scheduled vulnerability scans and a penetration test register are included.
Who you report to, and within what deadlines
The Article 23 NIS2 deadlines are the same across all transpositions — what differs is the regulator, the reporting channel and the names of entity categories. Switch the legal framework to the country you operate in.
| Regulator | the competent national authority / CSIRT of the member state (national CSIRT) |
|---|---|
| Reporting channel | the competent national CSIRT |
| Legal basis | Directive (EU) 2022/2555 (NIS2) |
| Implementing regulations | set by each member state's national transposition |
| Entity categories | essential entity · important entity |
| Reporting deadlines | early warning within 24 h · notification within 72 h · final report within 1 month |
The reporting channel, the register and the exact deadlines are set by each member state's national transposition.
What Vigil does — in detail
An overview of the system's functional areas. All security-relevant operations — including configuration changes to Vigil itself — are written to the same immutable audit trail.
Event hash chain
Append-only writes, every event cryptographically linked to the previous one; integrity verification with a single command.
Merkle anchoring
Periodic anchoring of the chain root outside the system — integrity remains provable even if the server is compromised.
Retention and WORM archive
Tiering: full-text searchable for 90 days, queryable up to 12 months (index reclaimed), immutable archive up to 24 months — each segment is sealed and its digest verified.
Unified event schema
Normalization of all sources: timestamp, actor, action, resource, tenant, IP, outcome, severity. Versioned action dictionary.
Detection rules
Declarative rules (YAML) mapped to MITRE ATT&CK: password guessing, permission changes outside working hours, bulk exports and deletions, DoS spikes.
False-positive management
Mandatory alert closure (true / false / benign) and a continuous FP metric — monitoring that never cries wolf over time.
Source watchdog
Ensures every connected system is actually sending events; a source going silent is an alert in itself.
Article 23 incident workflow
Alert-to-incident escalation, tracking of the 24 h / 72 h / 1 month deadlines, documentation for CSIRT reporting.
Article 21 self-assessment
Continuous assessment of measures — access management, MFA, encryption, backups, suppliers — with evidence from live operations.
Client portal
The customer sees their security posture, incidents, reports, invoices and contracts — strictly within their own tenant.
Monthly report (PDF)
Executive summary of events, alerts, incidents and compliance status; a snapshot of the figures is retained for audit.
DPA · SLA · billing
Data processing agreement and SLA generated from tenant data; DPA signature and plan changes are audit events in the hash chain.
Identity pseudonymization
Identities in events protected with a per-tenant key (HMAC); crypto-shredding — destroying the key renders the data unreadable.
Multi-tenant isolation + RBAC
Strict customer separation with admin / operator / client roles; isolation verified by an automated cross-tenant pentest.
SDK · HTTP · syslog · shipper
Drop-in SDK for applications, HTTP ingest, syslog; log shipper with mappers for existing logs without touching your systems.
Active defense and pentests
Automatic gateway hardening during an attack with rollback once it subsides; orchestration of vulnerability scans and purple-team scenarios.
A monitoring system that is itself under watch
A security tool must withstand stricter criteria than the systems it protects. Vigil is therefore continuously tested with load, simulated attacks and disaster recovery — and it monitors itself.
245 automated tests in CI
Every code change passes the full test suite — from chain integrity through detection rules to tenant isolation.
Purple-team harness — 24 attack scenarios
Simulated attacks run against an isolated instance and verify that the detections actually catch what they are supposed to catch.
Load and disaster-recovery testing
60 minutes at 100 events/s with a p95 response of 28.9 ms; disaster recovery over 662,000 events within 32 seconds with no loss of the trail.
Tenant isolation pentest
Automated attempts to access another tenant end in denial — isolation is not a claim, it is tested.
Dogfooding — Vigil watches Vigil
The system logs its own logins, configuration changes and administrative actions into the same immutable trail it provides to customers.
From the first source to full monitoring in three steps
Onboarding is designed to require no rebuild of your systems — we connect to what you already log and add depth incrementally.
Connection and trial
We set up your tenant and connect the first event source — typically within 2 hours. During the 30-day trial you see your own data in your own dashboard, with no commitment.
Implementation
We connect the agreed systems (SDK, HTTP, syslog, log shipper), tune detections to your operations, populate the asset and supplier register and sign the DPA + SLA. We train your people.
Operations and monitoring
Continuous collection and detection, incidents handled within statutory deadlines, a monthly executive report and documentation kept ready at all times for an audit or a regulator's inspection.
Transparent plans by organization size
Monthly subscription with no hidden items. Prices are final — we are not VAT registered; valid from August 1, 2026. A one-off implementation fee is added to the plan based on the size of the environment.
Monthly plans
Trial
- Full system functionality
- 1 event source, 5 devices
- 1-month retention
- Connected within 2 hours
Start
- 3 sources, 25 devices
- Core detections: logins, brute-force attacks, permission changes
- Tamper-evident audit
- Monthly report · 6-month retention
Standard
- 10 sources, 100 devices
- Everything in Start + NIS2 module
- Asset and supplier register
- Incidents with 24 h / 72 h / 1 month deadlines
- Article 21 self-assessment · 12-month retention
Enterprise
- Unlimited sources and devices
- Active gateway defense
- Penetration test orchestration
- Dedicated instance · 24-month retention
On-prem license — data never leaves your network
Vigil runs on your infrastructure. The price includes the license, updates and support; we deliver installation, a runbook and administrator training, while you operate the server and handle backups yourself. Suitable for organizations with strict data sovereignty requirements.
One-off implementation
Start
1 site, up to 25 devices, 3 log sources. Installation, source onboarding, core detections tailored to the environment, 4 hours of training, handover protocol.
Standard
Up to 100 devices, 10 sources, the NIS2 module including a populated asset and supplier register, integration of 2 of your own applications, detection tuning, 8 hours of training.
Enterprise
Multiple sites, over 100 devices, custom integrations, migration from an existing SIEM, active gateway defense, documentation for audits and regulator inspections.
Additional services
NIS2 entry audit and gap analysis
Environment review, comparison against the law and Article 21; the deliverable is a findings report and a prioritized action plan.
Penetration test of a website or application
Automated scan with manual verification of findings; a report with evidence and recommendations, retest after remediation.
Purple team exercise
A simulated attack against an agreed scenario, verifying whether monitoring catches it and whether people respond correctly.
Incident standby
Guaranteed intervention by a security specialist during an incident, including help with reporting within the Article 23 deadlines.
Connecting an additional system
A log source or application beyond the plan's scope — via SDK, HTTP interface or syslog.
Employee training
Security awareness and hands-on system operation, on site or online.
Representation during a regulator's inspection
Preparation of documentation and participation in the inspection or in resolving an incident report.
Custom requirements
Custom integrations, specific reports or detections — we will be glad to prepare a quote.
Commercial policy: 15% discount for two years paid in advance · 30% for non-profits and schools · 40% for the first customer in a segment in exchange for a reference · monthly payment without an annual contract +20%. Partner program for integrators: 15% commission on implementation and 10% on operations.
Frequently asked questions
How does Vigil relate to Praetorix?+
Praetorix is a GRC tool for compliance management — asset inventory, risk analysis, SoA and audit deliverables. Vigil is its operational twin: continuous security monitoring — event collection and detection (SIEM), an immutable audit trail and incident management within NIS2 deadlines. Together they cover both governance and operations; each can also be deployed on its own.
What does a "tamper-evident" audit trail mean?+
Every event is cryptographically chained to the previous one (hash chain) and the chain is periodically anchored outside the system (Merkle tree). Any later modification or deletion of any event is mathematically provable. The audit trail therefore serves not only operations, but as evidence before an auditor, a regulator and in potential litigation.
Does Vigil cover NIS2 obligations?+
Yes — the technical measures of Article 21 (monitoring, logging, access management, continuity), including self-assessment and inspection-ready documentation, and the Article 23 incident reporting process with deadline tracking: early warning within 24 hours, notification within 72 hours and a final report within 1 month. The Standard plan is designed precisely for entities falling under NIS2.
Does Vigil run in the cloud or on-premise?+
Both. Standard plans run as a managed service on EU infrastructure. The On-prem plan runs Vigil on the customer's infrastructure — data never leaves their network; we deliver installation, updates, a runbook and administrator training.
What about personal data protection (GDPR)?+
Identities in events are pseudonymized with a key bound to the specific customer (HMAC), and when the legal basis expires, crypto-shredding is applied — destroying the key renders historical data permanently unreadable. Onboarding includes a data processing agreement (DPA); its signature is itself recorded as an event in the audit chain.
How quickly can Vigil be deployed?+
A trial tenant with its first event source is connected within 2 hours. The Start implementation takes approximately 10 calendar days, Standard 21 days and Enterprise 45 days — calendar time includes the customer's own cooperation (access, approvals); our actual work amounts to 16 to 120 hours depending on scope.
Request a Vigil demo
Fill in the form — we will create a tracked ticket and get back to you within 24 hours with a proposed demo date. A trial tenant with your first event source can be connected within 2 hours.
- No obligation, no cost
- A tracked ticket with a reference number
- A demo on your own data
- 30-day trial with full functionality
Get monitoring that stands up to the regulator
Write to us or request an access ticket — within 24 hours we will get back to you with a proposed date for a demo on your own data.