Skip to content
Vigile AI

Vigile AI · Enterprise

Every risk in your Microsoft 365 estate, found and owned.

Exposed files, risky sign-ins and shadow apps. Rated, tracked and closed in one place.

  • 94%

    of exposures remediated

  • 12x

    faster risky sign-in detection

  • 6h

    saved per analyst, weekly

Why Vigile

Your Microsoft 365 tenant is your largest attack surface, and the hardest one to see.

Your people, their sign-ins, the apps they approve, the files they share, and the outside identities who still have access. Most of your Microsoft 365 security surface is invisible until something goes wrong.

  • Shadow-app consent accumulates silently

    An app approved once keeps access long after the person leaves.

  • Sensitive data sits in shared files

    A customer spreadsheet, a config file with an API key. One link away from leaving.

  • External access never gets cleaned up

    Contractors and vendors finish, but the permissions stay.

  • Failed sign-ins are noise, until they are not

    The one account under attack looks like every other failed login.

  • Findings do not become work

    Detection without an owner, a status and a record does not reduce risk.

It joins identity and data

A file finding only matters when you know who can reach it. A risky sign-in matters more when that person can reach sensitive files. Vigile shows both on the same screen.

  • Most tools do identity or data. Vigile shows the intersection.
  • Every finding is traceable to the person who can fix it.

Findings become work

Critical exposure becomes a case with an owner, a status and a recorded history. Every action is captured, so nothing is chased twice.

  • Public, sensitive files auto-become tracked cases.
  • The person who can fix it is one click away.

Platform

One platform, every kind of exposure.

Four pillars and the external half, from one connection to your Microsoft 365 and Entra ID tenant.

Coverage

Read-only across the Microsoft 365 services you already run.

One connection, owner-approved and revocable.

  • Entra ID
  • Exchange Online
  • SharePoint
  • OneDrive
  • Microsoft 365 Groups
  • Third-party apps

Administration

The controls underneath every page

  • Microsoft 365 and Entra ID connection

    Directory, mailboxes, drives, sign-ins and apps.

  • Automatic daily refresh

    Daily, plus on-demand scans.

  • Licence awareness

    Gated areas say what unlocks them.

  • Roles and Organization Users

    Admins, users and revocation in one place.

  • Settings and accountability

    Two-factor, activity log, subscription.

  • Global Search

    Search by email, phone, card or IP.

Pillar 1

Identity and Sign-in Risk

Who your people are, what they sign into, and where authentication is failing. Identity risk, seen across the whole tenant rather than one account at a time.

Organization

One screen for the whole tenant.

  • A 0 to 100 posture score for the tenant.
  • Searchable directory with risk and MFA status.
  • A per-employee exposure graph.
VIGILE AI
37Posture

Employees

8

In breach data

5

Avg. risk

41

EmployeeRiskMFA
Alex MorganMediumEnabled
Priya NairHighEnabled
Jordan LeeLowDisabled

Exposure Graph

Start from a person, not a queue.

Every employee carries their own exposure. The graph gathers everything the tenant knows about one person, public files, sign-in failures, breach data and app permissions included, and rates each bucket, so a review begins with a name and each finding stays traceable to the fix.

AM

Employee at risk

Alex Morgan

Critical risk86

8 exposure types · 73 findings

Anonymous link scan

Critical

Public files

4 findings

Files exposed through an anonymous public link.

Identity provider

High

Failed sign-ins

12 findings

Failed or anomalous sign-in activity was detected.

Dark web monitoring

Critical

Breach data

2 findings

Credentials found in known breach data.

OAuth grant audit

Medium

Write access to apps

5 findings

Applications have write access to corporate resources.

File scan

Critical

Sensitive files

37 findings

Sensitive files accessible to this employee.

OAuth grant audit

High

Unverified OAuth apps

3 findings

Non-verified apps hold sensitive permissions.

Endpoint protection

High

Malware exposure

1 findings

Malware signals detected on associated endpoints.

Sharing audit

Medium

Shared to external users

9 findings

Items shared with users outside the organization.

Exposure graph for one employee. Eight exposure types are arranged around the person, two on each side: public files and sensitive files across the top, failed sign-ins and unverified OAuth apps beside them, breach data and malware exposure below, and write access to apps and items shared to external users across the bottom. The employee sits at critical risk with a score of 86 across 73 findings.

Authentication Risk Monitor

Separate noise from the takeover happening now.

  • Named incidents: brute force, spray, credential stuffing.
  • Most-targeted employees, ranked by failed attempts.
  • A tracked workflow from Open to Closed.
VIGILE AI
Distributed Brute ForceCriticalCredential StuffingHighPassword SprayMedium
EmployeeApplicationFailure type
Alex MorganOutlookInvalid password
Alex MorganSharePointBlocked by conditional access
Sam OkaforTeamsInvalid password

App Risk Monitoring

Every consented app, and what it can reach.

  • A shadow-app consent audit: what each app can reach, and who approved it.
  • Every permission in plain language, rated by sensitivity.
  • Risk flags for unverified or background access.
VIGILE AI
Application inventory12 applications
ApplicationPermission risk
Contoso ReportsHigh
Mail Sync UtilityCritical
Calendar WidgetLow
Drive BackupMedium

The Mail Sync Utility app holds organization-wide mail and file permissions granted by 2 disabled accounts.

Pillar 2

Data Exposure

What is inside OneDrive and SharePoint, and how exposed it is.

Data Intelligence

Find the customer records, the API keys, the folder of contracts.

Once a file is shared by link, the exposure is real whether or not anyone intended it.
  • Detects SSNs, cards, passwords, API keys, IBANs and private keys.
  • Four sharing states: Private, Users, Organization, Public.
  • Notify the owner in one action, then export a per-file PDF.
VIGILE AI

Drives

6

Files scanned

18,402

Sensitive

37

Exposure

4.2%

Sharing states

PrivateUsersOrganizationPublic
FileOwnerSharingSeverity
payroll_q3.xlsxDana WhitfieldPublicCritical
customer_export.csvPriya NairOrganizationHigh
api_keys.txtAlex MorganUsersMedium

Your data stays yours. Contents are detected, never stored and never displayed. You see the category, the count and the confidence.

Data Lifecycle Risk

See which sensitive data has outlived the reason it was kept.

A file nobody has opened in two years is still a record you are responsible for.
  • Filter to files untouched for 60, 90 or 120 days.
  • Days inactive is colour-coded so the oldest stand out.
  • Export the inactive inventory as a report.
VIGILE AI
Untouched for60 days90 days120 days
FileDays inactiveSeverity
salary_review.xlsx603 daysHigh
vendor_contracts.zip491 daysMedium
old_backup_keys.pem385 daysCritical

Pillar 3

Access Governance

Who outside the company can reach your files, and the policy that decides what gets scanned.

External Access

The list nobody has: every outside account with direct access to your files.

The access stays, because nobody has a list of it.
  • Who they are, and the email they access your files with.
  • Provider and domain, a clue about the identity.
  • Reach: files accessible, and how many hold sensitive data.
  • Access level from real permissions: read, edit or full control.
  • A risk verdict with the reasoning, and the files behind it.
VIGILE AI
External users with access9 accounts
External accountRisk
m.reyes@partner-contoso.comCritical
audit@northwind-audit.comMedium
unknownHigh

Recommended: revoke access for m.reyes@partner-contoso.com. 4 of the reachable files contain sensitive data.

The recommended corrective playbook

These appear as guided recommendations in the product. Execution actions are still being wired up, so they are presented here as guidance, not one-click fixes.

  1. 1.Revoke external access

    No longer needed, especially for sensitive files.

  2. 2.Downgrade to read-only

    Ongoing relationship at too high a level.

  3. 3.Quarantine sensitive files

    Reachable content that needs moving or restricting.

  4. 4.Disable sharing links

    Access via a link, not a direct grant.

  5. 5.Request access justification

    Why is this access still needed?

  6. 6.Notify file owners

    Owner confirms the access is still needed.

  7. 7.Schedule access review

    Acceptable now, revisit later.

Pillar 4

Remediation and Reporting

Where exposure becomes work you can measure.

Remediation Center

Every critical finding, turned into a case with an owner, a status and a record.

Every other page tells you something. This is where you track what is being done about it.
  • Public, sensitive files become cases automatically.
  • Each carries the file, owner, severity and a VIG- reference.
  • Remediation rate and unresolved risk, tracked by age.
VIGILE AI

Total risks

37

Needs attention

21

Remediation rate

43%

New today

5

Severity breakdown

Critical6
High11
Medium14
Low6

Unresolved by age

< 24h5
1 to 3d7
4 to 7d4
> 7d5
Case queue
FileSeverity
payroll_q3.xlsxCritical
customer_export.csvHigh
api_keys.txtMedium

Reports

Evidence-ready, generated on demand

Generated on request as a branded PDF for compliance reporting: organization, date, who generated it, page numbering. Your filters are what you get, and exports are never truncated.

  • Organization Report
  • MFA Report
  • File Report
  • File List Report
  • Data Lifecycle Risk Report
  • Risk Intelligence Report
  • Case Management Report
  • Breach, Subdomain and Domain Impersonation Reports
  • AI Analysis and Summary

Alerts

The right person, at the right moment.

  • New exposed files detected
  • Sensitive file needs action
  • External access granted
  • Sign-in from a new address
  • Daily security summary
  • Reports ready
VIGILE AI

Action required: sensitive file detected

Contoso Ltd · Vigile AI

A file you own contains sensitive data and is publicly shared.

File

payroll_q3.xlsx

CriticalPublic link active

Sent to Dana Whitfield

Breach & Brand

What has already leaked, and who is impersonating you.

Everything above finds exposure inside your Microsoft 365 environment. This is the external half.

Domain Impersonation

Domains registered to look like yours, each listed with its IP address, geolocation and name server.

  • Filter by monitored domain, to see which brand is targeted.
  • Submit a takedown with abuse type, impersonated domain and evidence.
  • Track it from request received to takedown processing, exportable as PDF.

Takedown lifecycle

  1. Request received
  2. 2Under review
  3. 3Takedown processing

Email updates at every stage, including approved, completed or unsuccessful.

VIGILE AI
Look-alike domains6 domains
DomainName server
contoso-secure.comns1.contoso-secure.com
contos0.comns2.contos0.com
contoso-login.comns1.contoso-login.com

Also monitored

Earlier-stage exposure. Supported, but secondary to the identity, data and access picture above.

  • Breach Data

    Exposed credentials tied to your domains, with a validation status you control and one-click case creation.

  • Third Party Exposure

    Credentials leaked through your vendors and partners rather than your own systems.

  • Subdomains Exposure

    Which subdomains appear in breach data and how heavily, so you know where exposure concentrates.

Who it is for

Everyone who owns a piece of the answer.

Each role gets a starting point, and a shared view of the same posture.

CISO or Head of Security

Posture, remediation rate and ageing, across identity and data.

Organization score to Remediation Center

SOC or Analyst

Pre-correlated incidents and a drillable failed sign-in queue.

Authentication Risk Monitor

IT or Microsoft 365 admin

Shadow-app consent audit and external-access review.

App Risk Monitoring and External Access

Data Protection or Compliance

Discovery, retention controls and scan policy.

Data Intelligence and Data Lifecycle Risk

Legal or Brand

A takedown workflow with a documented lifecycle.

Domain Impersonation

Executive or Board

Board-ready PDFs with generation provenance.

Reports catalogue

Every feature at a glance

The whole platform, in one index.

Nine areas, grouped so you can find exactly the capability you need.

  • Security score
  • Employee directory
  • Organization group emails
  • Headline counts
  • Breach activity trend
  • Employee Security Graph
  • Employee profile
  • Investigation tabs
  • Organization and MFA reports

Get started

Three steps to your first posture.

No agents to deploy, no data to migrate. You connect once and the platform does the rest.

  1. 01

    Connect read-only

    Owner-approved, scoped to read-only, revocable any time.

  2. 02

    Vigile assesses automatically

    Identity, data, access and apps, evaluated together. Refreshed daily.

  3. 03

    Findings become tracked work

    Cases with a VIG- reference, an owner, a status and an audit trail.

Common questions

What security teams ask us first.

If your question is not here, book a walkthrough and we will answer it against your own tenant, with your own data.

No. The engine reads file contents to detect findings, but contents are never stored and never displayed. You see the finding category, the count and the detector confidence, not the data itself. Private files are excluded by default unless you deliberately extend the policy.

See your own tenant. In one session.

We connect to a demo or your environment, then show you in your own data who is targeted, what is exposed, and the queue that closes it out.

Get started