Catch Supply Chain Attacks, Not False Alarms.
Vigilance compares what you run with the update about to replace it. It names only the files that gained a new power, like reaching the internet or reading your keys.
One file. No agent. Mac, Linux, Windows and the BSDs.
In one week of November 2025, attackers backdoored 796 packages that millions of builds pull in every day. Every one arrived as a normal update.
How It Works
Three steps. There is no fourth.
-
Point It at a FolderAn install, a container image, a package, a build output. The first run learns every file there and what each one can do.
-
Take the UpdateRun Vigilance again. It compares what arrived against what it learned.
-
Read the One Line That MattersIt names any file that gained a power. Most days it names nothing.
One file to install, nothing to configure. It runs on Mac, Linux, Windows and the BSDs. It reads inside deb, rpm, npm, pip, containers, MSI, ISO and more. It never blocks a program, and it never sends your code anywhere. Pro opens no connection at all.
Who This Is For
Anyone who installs software they did not write.
You look after a fleet
One line enrols a machine. No agent, no console, one page for all of it.
You run an AI coding agent
It installs faster than you can read. This reads each one for you.
Your team takes updates
It stays quiet on the normal changes and names the one file that matters.
You ship your own builds
It names the file your build produced that none of your inputs explain.
Pricing
Free covers every machine you have. Pro adds offline.
Free Forever
$0/mth
Needs a network
- Every feature
- Unlimited machines
- Sends telemetry (what that means)
- Support queue
Cancel any time. No lock-in.
Early adopter? Get Pro free for two years for your logo and a short quote.
The same check runs on every one. Vigilance catches a poisoned update before it ships.
FAQ
How is this different from antivirus?
Antivirus finds files it already knows are bad. Vigilance finds new behaviour in an update that looks clean.
Is this file integrity monitoring?
It does that job and one more. A file integrity checker tells you a file changed. Vigilance tells you what the change lets that file do. See file integrity monitoring, or FIM for Windows.
Will it flood me with alerts?
Most days it reports nothing. A normal update changes files but gains no new power, so it stays quiet. It speaks up only when a file can suddenly do more.
How do you tune it?
We scan new software as it ships and tune the checks with what we learn. The goal is fewer false positives. There is no CVE list or threat feed behind it. A program can only be written in so many ways to reach the internet, run a command, or read your keys. We read for those.
Does it send my files anywhere?
Never your files. Pro opens no connection at all. Free posts a signed report of each file hash and the powers found in it. Never your code, never a path, never a name.
Does it need the internet?
Pro does not. It works fully offline, even air-gapped. Free needs the internet to run.
Can it look inside packages and archives?
Yes. It reads inside deb, rpm and npm packages, and inside xz, zstd, lz4, 7z, MSI, CAB, xar, ISO and squashfs. Each reader is hand-written with no dependency. A format it cannot open yet becomes a loud finding, never a quiet pass.
Is it open source?
No. The people who poison updates work behind closed doors. The people who catch them should too. If we published how the checks work, we would hand attackers the answer key. The transparency we can offer is on the Verify page: every download is signed, and you can check yours before you run it.