Catch supply chain attacks without the noise.

An attacker hides one bad file inside a normal software update. The rest of the update is real, so a list of changed files tells you nothing. Vigilance points at the one file that can suddenly do something it could not do before.

See pricing Talk to us

19things it looks for
18systems it runs on
0data sent to us
1file to install

Point it at a folder. That is it.

The first run remembers what is there. Every run after that tells you what changed. No setup, no rules to write, no settings.

vigi
$ vigi ./node_modules

  vigi  node_modules
       2,481 files now, 2,480 last time (run 14)

  LOOK HERE  1 thing to read. Nothing else changed.

    chalk/postinstall.js  412 bytes
      NEW FILE. It was not here before.
      It runs during an install.
      It downloads something and runs it.

  Ask before you install this one.

What it tells you

A new file arrived that can run commands

It can run programs, download things, or read your saved passwords. Some of these run on their own, the moment you install.

A file can suddenly do more than before

Yesterday it only read a file. Today it can run commands. A normal version bump stays quiet.

A file started talking to a new place

Same file, same job, but it now downloads from somewhere it never used before.

Something changed inside a zip or a container

It opens them up and reads every file inside, so a swap buried in there still gets named.

Someone edited the file your AI assistant follows

One added sentence can tell a coding assistant to do something you never asked for. Any edit gets flagged.

Someone tampered with its own records

Editing what it remembers breaks the seal on it. Deleting it sets off an alarm that stays on until a person turns it off.

It keeps watching on its own

Answer two questions and it schedules itself, using whatever your computer already uses to run jobs. Nothing of ours sits running in the background. On Mac and Linux it also wakes up the moment a file lands. If somebody deletes the schedule, the next run says so.

One file to install on Mac, Linux, Windows and the BSDs. It never opens a connection and never holds a password, so it works on a factory floor or a machine with no internet at all. Nothing about your files ever reaches us.

Pricing

Every plan runs on your own computers. Nothing is sent to us on any of them.

Free

$0forever

One person, one computer.

  • Everything on this page
  • 1 computer
  • Watch as many folders as you like
  • It schedules itself
  • Help by email
Start free

Enterprise

Customone price a year

A whole company.

  • Everything in Pro
  • Unlimited computers
  • Keep the records off the machine
  • Install with no internet at all
  • A named person to call
  • A signed support agreement
Talk to us

What it does not do

It never blocks anything. It tells you, and you decide. It does not know good from bad, so it names the change and a person reads the update notes.

If somebody already owns the whole computer, they own this too. No file checker can honestly claim otherwise. The first copy you show it becomes the yardstick, so start from a version you trust.

See how it sits next to what you run.

Twelve straight comparisons, and one chart with all of them.

Compare the tools Talk to us