Vigile AI · Enterprise
Every risk in your Microsoft 365 estate, found and owned.
Exposed files, risky sign-ins and shadow apps. Rated, tracked and closed in one place.
- Who is at risk? Jump to the employee exposure graph.
- What data is exposed? Jump to data exposure.
- Who outside can reach it? Jump to external access.
- What are we doing about it? Jump to remediation and reporting.
94%
of exposures remediated
12x
faster risky sign-in detection
6h
saved per analyst, weekly
Why Vigile
Your Microsoft 365 tenant is your largest attack surface, and the hardest one to see.
Your people, their sign-ins, the apps they approve, the files they share, and the outside identities who still have access. Most of your Microsoft 365 security surface is invisible until something goes wrong.
Shadow-app consent accumulates silently
An app approved once keeps access long after the person leaves.
Sensitive data sits in shared files
A customer spreadsheet, a config file with an API key. One link away from leaving.
External access never gets cleaned up
Contractors and vendors finish, but the permissions stay.
Failed sign-ins are noise, until they are not
The one account under attack looks like every other failed login.
Findings do not become work
Detection without an owner, a status and a record does not reduce risk.
It joins identity and data
A file finding only matters when you know who can reach it. A risky sign-in matters more when that person can reach sensitive files. Vigile shows both on the same screen.
- Most tools do identity or data. Vigile shows the intersection.
- Every finding is traceable to the person who can fix it.
Findings become work
Critical exposure becomes a case with an owner, a status and a recorded history. Every action is captured, so nothing is chased twice.
- Public, sensitive files auto-become tracked cases.
- The person who can fix it is one click away.
Platform
One platform, every kind of exposure.
Four pillars and the external half, from one connection to your Microsoft 365 and Entra ID tenant.
Coverage
Read-only across the Microsoft 365 services you already run.
One connection, owner-approved and revocable.
- Entra IDDirectory and sign-ins
- Exchange OnlineMailboxes and sign-in activity
- SharePointSites, drives and permissions
- OneDriveDrives, files and sharing links
- Microsoft 365 GroupsShared mailboxes
- Third-party appsConsented permissions
Administration
The controls underneath every page
Microsoft 365 and Entra ID connection
Directory, mailboxes, drives, sign-ins and apps.
Automatic daily refresh
Daily, plus on-demand scans.
Licence awareness
Gated areas say what unlocks them.
Roles and Organization Users
Admins, users and revocation in one place.
Settings and accountability
Two-factor, activity log, subscription.
Global Search
Search by email, phone, card or IP.
Pillar 1
Identity and Sign-in Risk
Who your people are, what they sign into, and where authentication is failing. Identity risk, seen across the whole tenant rather than one account at a time.
Organization
One screen for the whole tenant.
- A 0 to 100 posture score for the tenant.
- Searchable directory with risk and MFA status.
- A per-employee exposure graph.
Exposure Graph
Start from a person, not a queue.
Every employee carries their own exposure. The graph gathers everything the tenant knows about one person, public files, sign-in failures, breach data and app permissions included, and rates each bucket, so a review begins with a name and each finding stays traceable to the fix.
Employee at risk
Alex Morgan
8 exposure types · 73 findings
Anonymous link scan
CriticalPublic files
4 findingsFiles exposed through an anonymous public link.
Identity provider
HighFailed sign-ins
12 findingsFailed or anomalous sign-in activity was detected.
Dark web monitoring
CriticalBreach data
2 findingsCredentials found in known breach data.
OAuth grant audit
MediumWrite access to apps
5 findingsApplications have write access to corporate resources.
File scan
CriticalSensitive files
37 findingsSensitive files accessible to this employee.
OAuth grant audit
HighUnverified OAuth apps
3 findingsNon-verified apps hold sensitive permissions.
Endpoint protection
HighMalware exposure
1 findingsMalware signals detected on associated endpoints.
Sharing audit
MediumShared to external users
9 findingsItems shared with users outside the organization.
Authentication Risk Monitor
Separate noise from the takeover happening now.
- Named incidents: brute force, spray, credential stuffing.
- Most-targeted employees, ranked by failed attempts.
- A tracked workflow from Open to Closed.
App Risk Monitoring
Every consented app, and what it can reach.
- A shadow-app consent audit: what each app can reach, and who approved it.
- Every permission in plain language, rated by sensitivity.
- Risk flags for unverified or background access.
Pillar 2
Data Exposure
What is inside OneDrive and SharePoint, and how exposed it is.
Data Intelligence
Find the customer records, the API keys, the folder of contracts.
Once a file is shared by link, the exposure is real whether or not anyone intended it.
- Detects SSNs, cards, passwords, API keys, IBANs and private keys.
- Four sharing states: Private, Users, Organization, Public.
- Notify the owner in one action, then export a per-file PDF.
Your data stays yours. Contents are detected, never stored and never displayed. You see the category, the count and the confidence.
Data Lifecycle Risk
See which sensitive data has outlived the reason it was kept.
A file nobody has opened in two years is still a record you are responsible for.
- Filter to files untouched for 60, 90 or 120 days.
- Days inactive is colour-coded so the oldest stand out.
- Export the inactive inventory as a report.
Pillar 3
Access Governance
Who outside the company can reach your files, and the policy that decides what gets scanned.
External Access
The list nobody has: every outside account with direct access to your files.
The access stays, because nobody has a list of it.
- Who they are, and the email they access your files with.
- Provider and domain, a clue about the identity.
- Reach: files accessible, and how many hold sensitive data.
- Access level from real permissions: read, edit or full control.
- A risk verdict with the reasoning, and the files behind it.
The recommended corrective playbook
These appear as guided recommendations in the product. Execution actions are still being wired up, so they are presented here as guidance, not one-click fixes.
1.Revoke external access
No longer needed, especially for sensitive files.
2.Downgrade to read-only
Ongoing relationship at too high a level.
3.Quarantine sensitive files
Reachable content that needs moving or restricting.
4.Disable sharing links
Access via a link, not a direct grant.
5.Request access justification
Why is this access still needed?
6.Notify file owners
Owner confirms the access is still needed.
7.Schedule access review
Acceptable now, revisit later.
Pillar 4
Remediation and Reporting
Where exposure becomes work you can measure.
Remediation Center
Every critical finding, turned into a case with an owner, a status and a record.
Every other page tells you something. This is where you track what is being done about it.
- Public, sensitive files become cases automatically.
- Each carries the file, owner, severity and a VIG- reference.
- Remediation rate and unresolved risk, tracked by age.
Reports
Evidence-ready, generated on demand
Generated on request as a branded PDF for compliance reporting: organization, date, who generated it, page numbering. Your filters are what you get, and exports are never truncated.
- Organization Report
- MFA Report
- File Report
- File List Report
- Data Lifecycle Risk Report
- Risk Intelligence Report
- Case Management Report
- Breach, Subdomain and Domain Impersonation Reports
- AI Analysis and Summary
Alerts
The right person, at the right moment.
- New exposed files detected
- Sensitive file needs action
- External access granted
- Sign-in from a new address
- Daily security summary
- Reports ready
Breach & Brand
What has already leaked, and who is impersonating you.
Everything above finds exposure inside your Microsoft 365 environment. This is the external half.
Domain Impersonation
Domains registered to look like yours, each listed with its IP address, geolocation and name server.
- Filter by monitored domain, to see which brand is targeted.
- Submit a takedown with abuse type, impersonated domain and evidence.
- Track it from request received to takedown processing, exportable as PDF.
Takedown lifecycle
- Request received
- 2Under review
- 3Takedown processing
Email updates at every stage, including approved, completed or unsuccessful.
Also monitored
Earlier-stage exposure. Supported, but secondary to the identity, data and access picture above.
Breach Data
Exposed credentials tied to your domains, with a validation status you control and one-click case creation.
Third Party Exposure
Credentials leaked through your vendors and partners rather than your own systems.
Subdomains Exposure
Which subdomains appear in breach data and how heavily, so you know where exposure concentrates.
Who it is for
Everyone who owns a piece of the answer.
Each role gets a starting point, and a shared view of the same posture.
CISO or Head of Security
Posture, remediation rate and ageing, across identity and data.
Organization score to Remediation CenterSOC or Analyst
Pre-correlated incidents and a drillable failed sign-in queue.
Authentication Risk MonitorIT or Microsoft 365 admin
Shadow-app consent audit and external-access review.
App Risk Monitoring and External AccessData Protection or Compliance
Discovery, retention controls and scan policy.
Data Intelligence and Data Lifecycle RiskEvery feature at a glance
The whole platform, in one index.
Nine areas, grouped so you can find exactly the capability you need.
- Security score
- Employee directory
- Organization group emails
- Headline counts
- Breach activity trend
- Employee Security Graph
- Employee profile
- Investigation tabs
- Organization and MFA reports
- Failed sign-in list
- Most-targeted employees
- Named incidents
- Attack metrics
- Incident workflow
- Incident AI summary and history
- Geography and world map
- Attempt detail
- App estate size
- Usage and adoption
- Sign-in health
- Permission audit
- Who granted access
- Risk flags
- OneDrive and SharePoint scan
- Privacy by design
- Finding types
- Sharing states
- Exposure KPIs
- Monitored drives
- Files and Top Sensitive Files
- File drill-down
- Notify owner and reports
- Data Discovery Policy
- Inactive data inventory
- Age thresholds
- Days inactive
- Lifecycle report
- External user list
- Access level
- Risk rating and factors
- Files behind access
- Corrective playbook
- Auto-created cases
- Risk KPIs
- Analytics
- Case queue and inline workflow
- Case timeline and AI recommendations
- Exports
- Breach Data
- Third Party Exposure
- Subdomains Exposure
- Domain Impersonation
- Takedown requests
- Microsoft 365 integration
- Licence awareness
- Refresh and live updates
- Roles and Organization Users
- Settings and activity log
- Global Search
Get started
Three steps to your first posture.
No agents to deploy, no data to migrate. You connect once and the platform does the rest.
- 01
Connect read-only
Owner-approved, scoped to read-only, revocable any time.
- 02
Vigile assesses automatically
Identity, data, access and apps, evaluated together. Refreshed daily.
- 03
Findings become tracked work
Cases with a VIG- reference, an owner, a status and an audit trail.
Common questions
What security teams ask us first.
If your question is not here, book a walkthrough and we will answer it against your own tenant, with your own data.
No. The engine reads file contents to detect findings, but contents are never stored and never displayed. You see the finding category, the count and the detector confidence, not the data itself. Private files are excluded by default unless you deliberately extend the policy.
Through a single read-only connection to your Entra ID tenant. Only your organization owner can connect or disconnect, admin privileges are required on the Microsoft side, and the connection can be revoked at any time from your Microsoft admin portal.
Directory, employees, groups, OneDrive and SharePoint files, applications and permissions work on Microsoft Free. Sign-in history and app sign-in activity need Entra ID P1. Risk detections, risk levels and risk states need Entra ID P2. Anything your tier does not include appears as a labelled panel explaining what unlocks it, never a silent gap.
When Data Intelligence finds a file that is publicly shared and contains sensitive data, a case is created automatically with its own VIG- reference, an owner, a severity level and a full timeline. Status changes happen inline on the queue, and every change is recorded.
Data refreshes automatically every day, and you can run an on-demand scan whenever you need a current picture. There is no manual scan to remember: sync progress is reported per data type, and every page shows when it last refreshed.
Yes. The Data Discovery Policy controls whether private files are scanned, which exact filenames must always be checked, which filename tokens and fragments match, and which extensions are always treated as sensitive.
See your own tenant. In one session.
We connect to a demo or your environment, then show you in your own data who is targeted, what is exposed, and the queue that closes it out.

