Vigil8
Agentic GRC · six agents, one system of record

Technology risk, run by agents — governed by your people.

Vigil8 is the technology risk and compliance platform where AI agents don’t just summarise — they assess risk, draft controls, collect evidence and drive remediation inside the register, under the same lifecycle, permission and maker–checker rules your team works to.

  • Every agent action logged and attributable
  • Reversible in one click
  • Stops at a human gate
Command Center
7Critical open
23Controls due
94%Evidence fresh
118Agent actions / wk
Risk register · awaiting decision
Ref
Risk
Severity
Owner
State
RSK-0142
Third-party model access to customer PII
Critical
CISO
Agent working
RSK-0138
Privileged access review drift — cloud estate
High
Head of IT
Verified
RSK-0131
Unmapped ISO 27001 A.8 controls after migration
High
GRC Lead
Gap
RSK-0127
DR runbook untested for payments platform
Moderate
CTO
Agent working
ISO 27001 readiness78 / 93 controls
61 verified 17 drafted15 gaps
Aligned out of the box
  • ISO/IEC 27001:2022
  • ISO/IEC 20000-1:2018
  • ISO 31000:2018
  • ISO/IEC 42001:2023
  • SOC 2 · NIST CSF · DORA
UAE & Dubai regimes
  • UAE Information Assurance Regulation
  • DESC ISR v2
  • UAE PDPL (45/2021)
  • DIFC Data Protection Law No. 5
  • ADGM Data Protection Regs 2021
  • NCEMA 7000 business continuity
0%
less manual GRC effort in 12 months
0
domain agents in the managed fleet
0+
connectors over MCP and REST
0×
faster audit evidence turnaround

Figures are indicative of typical programmes and are agreed as targets during implementation planning, then reported against at every governance review.

Solutions

One platform across every technology risk discipline

Risk, compliance, audit, cyber, resilience and third party on a single relational system of record — not six products behind one login. Every discipline has an agent that owns its operational work.

Risk Management

Enterprise and technology risk on a 5×5 inherent-versus-residual model, with appetite, tolerance and treatment that derives its status from the work actually done.

  • Risk register & taxonomies
  • Inherent / residual assessment history
  • Appetite, tolerance & breach detection
  • Treatment plans, one approval gate
  • Key Risk Indicators & thresholds
Run by the Risk Agent · continuousExplore risk management

Regulatory Compliance

Multi-standard compliance with a common control framework — test once, report against every standard, and keep a Statement of Applicability that cannot disagree with the register.

  • Control library & common controls
  • Policies, versions & acknowledgement
  • Statement of Applicability (derived)
  • Regulatory change & horizon scanning
  • Exceptions & accepted exposure
Run by the Controls & Policy agentsExplore regulatory compliance

Internal Audit

Risk-based audit from universe to closure, with evidence requests issued and chased automatically and findings landing in the same register as every other issue.

  • Audit universe & annual plan
  • Engagements, fieldwork & reporting
  • Evidence requests (PBC) tracked to receipt
  • Findings & management actions
  • Tamper-evident evidence bundles
Run by the Audit AgentExplore internal audit

Cyber GRC

Security control assurance driven by live telemetry. Agents attest controls straight from Entra ID, AWS, CrowdStrike and Wiz — and flag exactly what still needs a human.

  • Continuous control monitoring
  • Auto-attestation from connected tooling
  • Incident response & notification clocks
  • Vulnerability & posture evidence
  • Security awareness & training
Run by the Evidence Agent · autonomousExplore cyber grc

BCM & Resilience

Continuity and disaster recovery tied to the services, suppliers and systems they protect — with test cycles that raise real work when a plan fails or goes stale.

  • Continuity & DR plans with RTO / RPO
  • Business impact analysis
  • Scheduled plan testing & results
  • Dependency & coverage gap reporting
  • Operational resilience reporting
Plan drafting & staleness detectionExplore bcm & resilience

Third-Party Risk

Supplier tiers derived from criticality and data sensitivity — never chosen — so assessment depth and cadence follow the exposure rather than whoever fills the form.

  • Supplier register & derived tiering
  • Questionnaire designer & portal
  • Certification & SOC 2 expiry tracking
  • Automated reassessment cycles
  • Concentration & fourth-party view
Questionnaire analysis & chasingExplore third-party risk
The platform

Four things that make this different

A register that scores risk properly. A command centre that explains its own numbers. A fleet of agents that does the work. And a builder that lets you wire agents to your actual tooling, control by control.

Risk that shows its working

Anyone can store a risk score. Vigil8 records how it was reached — a dated, attributable assessment with a rationale grounded in your actual control coverage, so the register survives the question "why is that a 9?"

  • 5×5 inherent and residualscored separately, with full assessment history rather than a single overwritten number
  • Appetite and toleranceheld per category and entity, with breaches surfaced automatically
  • The AI proposes the inputs, never the numberscoring arithmetic stays deterministic and reproducible
  • Treatment has one gate — on the plandelivery status derives from the underlying tasks

See the risk module

Risk Intelligence
Inherent risk · 5×578 risks scored
5
2
1
3
1
4
1
4
6
2
3
3
7
9
4
1
2
5
8
6
2
1
4
3
2
1
1
2
3
4
5
LowModerateHighCriticalImpact ↑ · Likelihood →
The live chain

From a sentence to signed-off evidence — without leaving the platform

Describe an exposure in plain language. Five steps later you have a scored risk, a drafted control cited to a standard, live evidence from your own tooling, and an attestation waiting for a human signature. Agents do the work; people keep the authority.

1

Compose the risk

A sentence becomes a structured risk — category, owner, inherent likelihood and impact, each with a rationale drawn from your own control coverage.

Agent
2

Draft the control

Objective, control activity, type, frequency, owner and a written test procedure — pre-cited to the ISO clauses it satisfies.

Agent
3

Bind the evidence source

The platform names which connected system can prove the control, over which transport, and exactly what artefact it will return.

Person
4

Collect and verify

The agent calls the bound tool, attaches the artefact with full provenance, and flags anything that doesn’t actually prove the control.

Agent
5

Attest — and stop

The attestation enters awaiting sign-off. It does not count toward compliance until an independent checker agrees.

Person
Frameworks & standards

Adopt a standard in a review, not a project

Hold every standard concurrently with its full clause structure. Controls cite clauses many-to-many, so one control tested once reports against ISO 27001, ISO 20000-1 and your customer’s security schedule at the same time.

  • AI cross-maps your existing libraryto a newly adopted standard — already covered, partially covered, genuinely new
  • Clause citations suggested with confidence ratingsand a one-line rationale, for you to confirm
  • The Statement of Applicability is derived, never storedfail a control test and the SoA changes without anyone editing it
  • Accepted gaps appear on the SoAso the document an auditor holds never overstates your position
Statement of Applicability
Statement of Applicability · ISO/IEC 27001:2022Derived, not maintained
Clause
Control
Decision
Evidence
A.5.1
Policies for information security
Applicable
Verified
A.5.7
Threat intelligence
Applicable
Agent drafted
A.8.16
Monitoring activities
Applicable
Verified
A.8.23
Web filtering
Excluded
Justified
A.8.28
Secure coding
Applicable
Gap
Status recalculated from evidence freshness on every change
Industries

Configured for the obligations you actually carry

The frameworks, taxonomies, questionnaires and notification clocks that apply to your sector, set up at implementation — not a generic library you spend six months pruning.

Financial Services

DORA, operational resilience, third-party concentration and regulator reporting.

Technology & SaaS

ISO 27001, SOC 2 Type II and continuous customer security assurance.

Healthcare

Special-category data, supplier control and breach notification clocks.

Energy & Utilities

NIS2, OT/IT convergence and critical dependency resilience.

Public Sector

Assurance frameworks, transparency obligations and audit scrutiny.

Manufacturing

Supply chain risk, ISO 20000-1 service management and continuity.

Outcomes

What changes in the first year

The three numbers customers hold us to. We’ll agree the baseline with you at implementation and report against it — not claim it and move on.

68%

less manual GRC effort

Evidence collection, chasing, attestation and reporting shift to the fleet. Your people move to judgement work — reviewing, deciding and signing. Measured against the pre-implementation baseline at month 12.

faster audit evidence turnaround

A request that took days of manual assembly becomes a self-service, tamper-evident bundle with chain of custody and its own stated gaps.

more controls under high assurance

Controls proven by automated testing rather than self-attestation. The compliance number stops being a number and starts being evidence.

Connectors & MCP

Your agents reach your estate — over MCP first

Twenty-two connectors across identity, cloud, security tooling, ticketing and workforce. Each declares which controls it can evidence, so the value of connecting a system is visible before you connect it.

  • MCP as the preferred transporttyped, discoverable tool calls over a Model Context Protocol server — selected by default wherever one exists, with REST as the fallback
  • Bring your own MCP serverVigil8 also publishes its own, so your other AI tooling can query GRC data under the same permissions
  • Every call loggedtarget, arguments, response summary, latency and outcome — recorded per call, exportable as audit evidence
Connectors & MCP
Vigil8 agent runtimeMCP first · least-privilege, scoped, logged
Entra IDIdentity · MCP
AWSCloud posture
JiraChange & actions
SplunkLog evidence
ServiceNowITSM tickets
GitHubSDLC controls
WorkdayJoiners / leavers
M365DLP & sharing
Every tool call is recorded with the agent, the scope and the artefact it produced
Agent governance

The platform is an AI system too — so we built it to be governed

Vigil8 will sit inside your ISO/IEC 42001 management system. These aren’t features we added for a questionnaire; they’re the reason the fleet can be trusted with authority at all.

Enforced, not instructed

Agent authority is enforced by the permission and lifecycle layer — not by a line in a prompt. An agent cannot make a transition the state machine forbids, or exercise a capability its principal doesn’t hold.

Maker–checker applies to agents

An agent’s output is a submission, never a completion. It can move work to awaiting approval; only a capability-holding human moves it to done. Self-approval is blocked for people and agents alike.

Determinism where it counts

Compliance figures, scoring arithmetic, SoA derivation, supplier tiering and bundle digests are computed, reproducible and never model-derived. The AI writes about the numbers; it doesn’t produce them.

Reversible by design

Any autonomous action can be undone in one click, with the reversal recorded. Blast-radius limits cap what a single run can touch, and a fleet kill switch stops everything instantly.

Graceful degradation

Every AI feature has a deterministic fallback. Pull the model endpoint and you still get a usable risk score, a drafted control and a working platform — degraded, never down.

Reconstructible after the fact

Trigger, principal, each reasoning step, each tool call, each record produced, the model version and the token cost — retained, queryable and exportable for your auditor.

Proof & recognition

Trusted where the consequences are real

Customer types rather than logos, so nothing is asserted that isn’t true. Swap these for cleared customer logos once you have written permission.

Global banking group

4,000 staff · DORA & ISO 27001

Tier-1 insurer

Operational resilience programme

Analyst recognition

Placeholder — add your citation, or delete this tile. Never substitute an award the company has not received.

Industry award

Placeholder — add your citation, or delete this tile.

We stopped buying "AI-powered" GRC and started asking one question: can it take an action, and can you show me the log? Vigil8 was the only platform where the answer to both was yes on the day of the demo.
Head of Technology Risk· Financial services group · 4,000 employeesIllustrative

See the chain run live — on your standards, in 45 minutes

We’ll take an exposure you describe on the call and take it through to signed-off evidence. Then we’ll pull the model endpoint out and show you the platform still works.

  • No slide-ware
  • Your scenario
  • Agent trace shown throughout