Vigil8
Contact

Let’s put an agent to work on your estate.

Whether you’re scoping a GRC replacement, writing an RFP, or just want to see whether agentic GRC is real — talk to someone who can answer at the level of the architecture, not the brochure.

< 1 day
Reply from a named person who can answer technical questions
0 min
Scripted live demo — your scenario, in a working environment
0 weeks
Sandbox proof of value, operated by your own practitioners
0 weeks
Phase 1 go-live from contract award
Get in touch

Tell us what you’re solving

The more you tell us about your standards, your estate and where the manual effort actually sits, the more useful the first conversation is. Everything is optional except name, email and message.

We reply to every enquiry within one working day, from a named person who can answer technical questions — not a queue. We’ll only use these details to respond.

Offices

Where we are

Data residency is selectable per tenant, independently of where our teams sit.

London

Headquarters
1 Finsbury Avenue London EC2M 2PF United Kingdom
Illustrative

Bengaluru

Engineering
Embassy TechVillage Outer Ring Road Bengaluru 560103, India
Illustrative

Dubai

Middle East
Gate Avenue, DIFC Dubai United Arab Emirates
Illustrative

New York

Americas
1 World Trade Center New York, NY 10007 United States
Illustrative

Addresses marked illustrative are placeholders — replace them with real, staffed locations before launch.

Trust summary

What we’ll confirm in writing, before you ask

The answers most procurement teams have to chase for three weeks. Ours are on the record from the first conversation.

Your data never trains a model

Not ours, not a third party’s. It’s a contractual warranty, not a policy page — and we’ll put it in the agreement before you ask for it.

Your data leaves whenever you want

Records, files, evidence, agent logs and configuration — in open, documented formats, at any time, at no charge, without needing our help.

Model routing is yours to set

Select the model or provider, including your own endpoint. Private, in-region and in-tenant deployment available where residency demands it.

Certified and independently tested

ISO/IEC 27001 certified, SOC 2 Type II, annual independent penetration testing with the executive summary shared — including testing of the AI layer specifically.

ISO/IEC 42001 documentation

Intended use, limitations, known failure modes, evaluation methodology and results — the documentation your own AI management system needs about us.

No AI behind a premium tier

Every capability on this website is in the quoted price. If consumption is metered, we give you a worked example at your volumes before you sign.

Frequently asked

The questions we get asked most

Fair question, and the right one. The test we’d apply: can it take an action in the register, and can you see the log?

Vigil8 has six persistent agents with a run cadence, a bound tool set, bound connectors, a configurable autonomy level and a named human owner — plus twelve governed tools they act through. Every run is reconstructible after the fact: trigger, principal, each reasoning step, each tool call, each record produced, the model version and the token cost. We demonstrate all of that live rather than describing it.

Four things, none of which is a prompt instruction. Agent authority is enforced by the platform’s permission and lifecycle layer, so an agent cannot make a transition the state machine forbids or exercise a capability its principal doesn’t hold.

There is a list of prohibited actions no agent may take at any autonomy level — publishing a policy, approving its own work, granting an exception, closing an incident, sending an external communication, deleting a record. Blast-radius limits cap what a single run can touch. And anything autonomous is reversible in one click, with the reversal recorded.

No — and this is structural, not configuration. An agent’s output is a submission, never a completion. It can move an attestation to awaiting sign-off, but a submitted attestation does not count toward compliance until a capability-holding human approves it.

Self-approval is blocked for people and agents alike. If a vendor tells you their agent "closes the loop" on control testing, ask who signed.

The product degrades; it doesn’t go down. Every AI feature has a deterministic fallback that returns a usable, explainable result — you will still get a risk score suggestion, a drafted control and a recommended evidence source from rule-based logic. The interface tells the user which path produced the output.

All record-keeping, workflow, approval, scheduling and reporting functions are fully operable with AI entirely disabled. We will demonstrate this by disabling the endpoint in front of you.

Never. Compliance percentages, scoring arithmetic, lifecycle transitions, Statement of Applicability derivation, supplier tiering, assurance banding and evidence bundle digests are all deterministic and reproducible.

The model influences inputs and writes the commentary; it is not in the path of any number that appears in an audit report. We will tell you exactly where that boundary sits, feature by feature — and if another vendor cannot, assume inference is in the path.

Phase 1 go-live within 12 weeks of contract, covering your primary standard, the control library, the risk register and the first two agents at suggest only. Autonomy is raised deliberately, per agent, once acceptance rates justify it — we would rather you trusted the fleet on evidence than on our say-so.

Migration from spreadsheets and document stores includes AI-assisted extraction of structured risks, controls and policies from your existing unstructured documents, with human validation of every record.

ISO/IEC 27001:2022, ISO/IEC 20000-1:2018, ISO 31000:2018 and ISO/IEC 42001:2023 ship with their full clause structure, and SOC 2, NIST CSF and DORA mappings are available. You can define your own frameworks and clause sets, and hold any number concurrently.

For the UAE, the regional regimes are held the same way: the UAE Information Assurance Regulation, DESC ISR v2 for Dubai government and semi-government entities, UAE PDPL (Federal Decree-Law 45/2021), DIFC Data Protection Law No. 5 of 2020, ADGM Data Protection Regulations 2021, and NCEMA 7000 for business continuity.

Because the IAR and DESC ISR both derive from ISO/IEC 27001, most of an existing control library maps straight across — the cross-mapping agent shows what is already covered, partially covered and genuinely new before you commit. And because controls cite clauses many-to-many, one control tested once reports against every standard citing it, which is what makes adopting a second or third standard a review rather than a project.

Separately from practitioners, and deliberately cheaply. A GRC platform that only the compliance team can afford to log into has failed — acknowledgement, training, incident reporting and exception requests all depend on the whole workforce being able to reach it.

We will state the portal user cost explicitly in any proposal, and we do not penalise organisation-wide rollout.

Still deciding what to ask?

We’ll send you the requirement set and scoring model we’d want an evaluator to use on us — 440 requirements, a weighted evaluation model, and eleven scripted demonstration scenarios.