What Vigilo does
Vigilo (Vigilo) is a security and compliance scanner. You submit a URL; we run a series of passive and, where authorized, active checks against it and produce a report. This policy covers the personal data we collect from you as a user of the service, and separately, how we handle data belonging to the sites we scan.
Data we collect from you
- Email address — required to submit a scan or create an account, used to identify your account and deliver scan results.
- Account and authentication data — if you sign in, our authentication provider (Clerk) manages your credentials; we store the resulting account identifier, not your password.
- Submitted target URLs — the sites you ask us to scan, and the reports we generate from those scans.
- Billing information — if you subscribe to a paid plan, payment details are collected and processed directly by our merchant-of-record payment provider; we receive only your subscription status and plan, never your card details.
- Operational logs — standard request logs and an audit trail of authorization decisions (what was scanned, at what tier, and why), kept for security and debugging.
How we handle data about scanned sites
A scan captures evidence — response headers, page content excerpts, and similar technical artifacts — needed to justify each finding in your report. Before this evidence is stored, any value that looks like a secret (an API key, token, or credential) is redacted; only a fingerprint of it is kept, never the raw value. Evidence bundles are stored for a limited period (90 days) and then deleted; the resulting report and score are retained for as long as your account exists.
Passive-tier scanning only ever makes requests a normal visitor or search-engine crawler would make. Active-tier scanning — path enumeration and deeper probing — only runs once we have verified you own or control the target, via a DNS record, a well-known file, or a meta tag you control.
Who we share data with
We use a small number of subprocessors to run the service: our cloud hosting and database provider, our email provider (for account and report notifications), our authentication provider (Clerk), our merchant-of-record billing provider, and an LLM provider used to generate plain-language remediation guidance for findings. Data sent to the LLM provider is limited to already-redacted finding summaries — never raw evidence or account credentials. We do not sell your data.
Your rights
You can request a copy of the data we hold about you, ask us to correct it, or ask us to delete your account and associated data, by emailing support@vigilo.io. If you are a site owner and want a scan of your site removed or want your site excluded from future scanning regardless of who submits it, see our Acceptable Use Policy.
Contact
Questions about this policy can be sent to support@vigilo.io.