VigilArch

platform

Everything a continuous review discipline actually needs, in one place.

Eleven real capability areas, all correlated against the same live architecture — not eleven disconnected tools you have to stitch together yourself.

discovery & inventory

A live inventory, not a spreadsheet someone remembers to update.

The foundation everything else correlates against — continuously refreshed, not exported once and left to rot.

Multi-cloud connectors

AWS, Azure, and GCP — live, continuously refreshed asset discovery across every account you connect.

On-prem network & firewall connectors

Cisco ASA, Check Point, and others — the on-prem estate stops being a blind spot cloud-only tools leave behind.

Full asset & system inventory

Ownership, criticality, and governance tier tracked per system — not just a flat list of resource IDs.

Technology & end-of-life tracking

Flags software approaching or past end-of-life before it becomes an incident, not after.

architecture & threat modeling

Diagrams that are connected to what's real, not drawn once in Visio.

Architecture as a living model — linked to live discovered assets, with real governance artifacts behind it.

Architecture diagramming

Diagrams generated from and linked to live discovered assets, with node-level detail and drill-down.

STRIDE threat modeling workbench

Manual, node-by-node modeling or a guided bulk pass that proposes findings across an entire diagram for review.

Data flow maps

Trace how data actually moves through a system — the real basis for a threat model, not an assumption.

Architecture Decision Records & principles

Real, structured governance artifacts — why a decision was made, not just what the diagram shows today.

risk & exposure correlation

Severity tied to your real architecture, not a standalone CVSS score.

The core correlation engine — connecting vulnerability data to the specific asset, trust boundary, and blast radius that make a finding actually matter.

a standalone CVSS score

CVE-2026-4471

9.8 CRITICAL

No architecture, no trust boundary, no reachability — just a number, floating on its own.

the same finding, correlated

VPC · trust boundaryLBDB2 hops from internetbehind 1 trust boundary→ Priority: Medium

Cross-domain risk graph

One real, structural graph spanning vendors, systems, AI systems, and capabilities — not four disconnected lists.

Vulnerability–exposure correlation

Findings tied to trust boundaries, connectivity, and asset role — actual reachability, not theoretical risk.

Blast-radius-aware remediation prioritization

Severity still leads, but ties break by how many real, connected things actually depend on the vulnerable asset.

The Composite Continuum Score

A single, transparent number — every sub-score visible, never a black-box formula, honestly blank until real data backs it.

compliance & controls

Controls that verify themselves against live connector data.

Real, ongoing compliance discipline — not a once-a-year evidence scramble before an audit.

Continuous control monitoring

Automated, connector-verified checks — a control's status reflects what's actually configured right now.

Policy management

A real draft → review → approve workflow, structured document numbering, and scheduled recertification.

Evidence requests

Time-boxed, token-based links for collecting evidence from anyone — no account required on their end.

Recertification campaigns & audit log

Scheduled attestation cycles and a complete, durable record of who did what, when.

vendor & third-party risk

See exactly what a vendor's risk actually touches.

Vendor risk that propagates — not a spreadsheet of vendor names disconnected from what they're actually connected to.

Vendor risk register

Track inherent and residual risk per vendor, not just a static approved-vendor list.

External vendor questionnaires

A real, no-login-required intake flow for a vendor to answer your own security questionnaire directly.

Vendor risk propagation

See exactly which of your own systems and Solution Design Reviews a given vendor's risk actually reaches.

solution design review

A real front door for new projects, not a Slack message to security.

Structured intake and review, tied directly into the same architecture and risk data as everything else.

SDR pipeline

A structured review workflow tied to real systems and diagrams, not a document that lives in someone's inbox.

Engagement intake

A real, structured front door for a new project or engagement request to enter the system.

CI/CD security gate

A real API endpoint your own pipelines can call directly — a genuine automated checkpoint, not a manual sign-off.

incident response

A real incident lifecycle, connected to everything else you track.

From the moment an incident is logged through corrective action — and a real-time signal the instant it happens.

Full incident lifecycle

Timeline, corrective actions, and notification obligations tracked against a single, real incident record.

Disaster recovery planning

Real DR plans and test scheduling, not a document that only gets opened during an actual outage.

Real-time webhook notification

A signed webhook fires the instant a real incident is created — your own tools know before anyone has to check.

ai governance

Govern your own AI systems, not just the assistant helping you review.

A genuinely separate discipline from Warden itself — an inventory of the AI your organization runs, with real risk tiering.

AI system inventory

Track the AI systems your own organization actually runs, distinct from general asset inventory.

AI risk tiering

A structured, documented judgment call on risk level — not an automated guess with no real basis.

warden — the ai copilot

An assistant that cites its sources and writes directly into your workbench.

Not a separate chatbot window — context-aware across everything else you're already looking at.

Context-aware across the platform

Understands the specific asset, diagram node, or finding you're looking at — not a generic, disconnected chat.

Cited provenance

Every suggestion cites its real sources — never an assertion with no basis you can check.

Writes findings directly into the workbench

STRIDE findings go straight into your review queue to accept, adjust, or discard — not left in a chat transcript.

platform & integrations

A platform other tools can actually connect to.

Real, external-facing surfaces — not a closed system you have to check manually.

Public read API

Systems, risks, and vendors — a real, stable, versioned contract for external scripts and integrations.

Outbound webhooks

Signed, real-time event delivery to your own tools — HMAC-verified, so a receiver knows it's genuine.

External auditor portal

Time-boxed, read-only sharing of specific approved policies — no account needed on the auditor's end.

identity & access

Real enterprise access control, not just an admin/user toggle.

Granular, auditable access — built for a real security team, not a single shared login.

SSO & SCIM

SAML-based single sign-on and automated user provisioning — access managed from your own identity provider.

Custom roles

Granular, tenant-defined permission bundles — not a fixed set of four roles that never quite fit.

Groups & separation of duties

Real organizational structure reflected in who can approve, review, and act.

Request a demo