Security
We’re early, and we’d rather say so here than have you find out later.
What follows is exactly what Vigil reads, what it stores, what it discards, and how to stop it — plus what we don’t yet have.
| What it reads | A connected project mailbox, read-only. It doesn’t read personal mail, it can’t send on your behalf, and it can’t modify or delete anything in your mailbox. |
|---|---|
| WhatsApp, if you connect it | Vigil links as a second device, the way WhatsApp Web does. It never sends a message, never marks anything read, never shows as typing and never appears online. It keeps messages and files only from the groups you attach to a project — one-to-one chats are discarded. |
| What WhatsApp sends us | When you first link your phone, it hands over its message history — including chats you haven’t attached to anything. That is how WhatsApp works: history is offered once, at linking, or not at all. Vigil keeps only your linked groups and discards the rest without writing it down. Received, not stored. This happens at linking only, not each time Vigil reconnects. |
| What it stores | Message metadata and body text, filed against a job. Attachments, in your workspace. Nothing is shared with any other workspace. |
| What it discards | Anything it can’t attribute to a job, and anything marked personal. |
| How to stop it | Revoke access from your own Google or Microsoft admin console at any time. No request to us required. On written request, the workspace and its contents are deleted within 30 days. |
| Where data lives | Microsoft Azure and MongoDB Atlas. state the exact region before publishing |
| Subprocessors | Azure (hosting, storage) · MongoDB Atlas (database) · Vercel (web delivery) · Anthropic (language model — content is not used to train models) · Microsoft Graph and Google (mailbox read). Clients are notified before this list changes. |
| Access control | Feature-level permissions by role. Workspace isolation enforced at the application layer. Full activity log on every record. |
| What we don’t have yet | No ISO 27001. No SOC 2. No penetration test yet. We’d rather list these than imply otherwise. |