VigilChain
Code-to-cloud risk visibility

Privacy Policy

What we collect, how we use it, who we share it with, and the rights you have.

Effective Date: May 6, 2026 Version 1.1

1. Overview

VigilChain, Inc. ("VigilChain," "we," "us," or "our") is a Delaware corporation. This Privacy Policy describes what personal information we collect, how we use it, whom we share it with, and the rights you have regarding that information.

This Privacy Policy applies to:

  • The VigilChain marketing website at www.vigilchain.com (the "Site");
  • The VigilChain Application Security Posture Management platform at app.vigilchain.com (the "Platform");
  • The VigilChain API at api.vigilchain.com (the "API").

Collectively, the Site, Platform, and API are the "Services."

Scope note. VigilChain's Services are currently offered to customers located in the United States. We do not currently support customers located in the European Economic Area, the United Kingdom, or Switzerland. If you are located outside the United States and interact with our Services (for example, by visiting the Site), your information is processed in the United States. If we expand our customer eligibility in the future, we will update this Privacy Policy with appropriate disclosures and safeguards.

2. Information we collect

When you visit our marketing website

When you visit www.vigilchain.com, we collect:

  • Analytics data via PostHog: page views, clicks, navigation paths, referrer URLs, approximate IP-derived location, browser and device type, and JavaScript exceptions. Anonymous visitors are not associated with a personal profile — our PostHog configuration creates person profiles only for identified users.
  • Form submissions when you submit the demo request or contact forms: the name, email address, company name, role, subject, and message content you provide. These submissions are processed through our API Gateway.
  • Technical logs from CloudFront, our content delivery network: IP addresses, user-agent strings, and request timestamps, retained for operational troubleshooting and abuse prevention.

When you use the Platform

When you create an account and use the Platform, we collect:

  • Account information: name, email address, organization name, job title, and role assignment.
  • Authentication material: a bcrypt-hashed password, a TOTP secret (if you enable multi-factor authentication), session identifiers, and any API keys you create. We never store your password in cleartext.
  • Invitation data: if you are invited to a tenant, the inviting administrator provides your email address, and we collect additional profile information when you accept the invitation.
  • Usage data: information about how you interact with the Platform — features used, pages viewed, actions taken, search queries, and performance timings — used to operate and improve the Services.
  • Audit logs: a record of security-relevant events in your tenant, including logins, configuration changes, permission changes, and administrative actions.

Customer Content submitted through the Services

When you connect sources (repositories, cloud accounts, scanners) or initiate scans, the Platform processes:

  • Source code during a scan, transiently, for the duration of the scan job.
  • Scan findings and metadata: file paths, line numbers, rule identifiers, vulnerability descriptions, code snippets associated with findings, severity, and related remediation metadata.
  • Asset and infrastructure metadata: repository names, branch information, CI/CD configuration files, container image references, cloud resource identifiers, service configurations, and network topology accessible through read-only cross-account roles.
  • Workflow integration data: finding information exchanged with your configured issue trackers.

Customer Content may incidentally contain personal data — for example, email addresses in source code comments, or usernames in configuration files. Where personal data appears in Customer Content, we treat it as Confidential Information under the Terms of Service and apply the same technical and organizational protections that apply to all Customer Content. You remain the controller of any personal data contained in Customer Content you submit.

Information from third parties

We receive information about you from third parties in limited cases:

  • If you authenticate through a single sign-on provider, the provider sends us the identifying information you authorize.
  • If someone invites you to a tenant, the inviting administrator provides your email address.
  • Our service providers may share operational information back to us — for example, delivery confirmations for transactional emails.

3. How we use your information

We use the personal information we collect to:

  • Provide, operate, and improve the Services;
  • Create and manage your account and tenant;
  • Ingest, deduplicate, correlate, and prioritize security findings across your connected sources;
  • Map the deployment chain between your repositories, container images, cloud services, and network exposure points;
  • Generate risk scores, finding context, and remediation guidance — including via AI-assisted analysis (see Section 10);
  • Send transactional communications — finding alerts, invitations, account notifications, and service updates;
  • Respond to your inquiries and support requests;
  • Detect, investigate, and prevent security incidents, fraud, abuse, and unauthorized access;
  • Comply with legal obligations and enforce our Terms of Service;
  • Communicate with you about product changes or optional announcements you have subscribed to;
  • Conduct product analytics on aggregated and de-identified data to improve the Services.

We do not use your personal information for third-party advertising, and we do not sell your personal information.

4. How we share your information

Service providers (subprocessors)

We engage the following service providers to operate the Services. Each is bound by contractual data-protection terms.

Provider Purpose Data processed Location
Amazon Web Services, Inc. Infrastructure hosting: compute, database, cache, object storage, email delivery, DNS, CDN, logging, secrets management. Production AI inference via Amazon Bedrock (Anthropic Claude served inside VigilChain's AWS account). All customer data categories, including AI prompts and responses for the production Bedrock surface United States (us-east-1)
Anthropic, PBC Claude model provider. On the production path, Claude is served via AWS Bedrock inside VigilChain's AWS account; Anthropic remains a contractual counterparty under Anthropic's Commercial Terms (two-layer DPA) but does not access prompts or responses on this path. The direct Claude API is used only for tenants that have configured their own Anthropic API key (Bring Your Own AI Key) and for internal operator tooling that does not process customer data. Source code excerpts and finding metadata, as needed to perform AI analysis United States
GitHub, Inc. (Microsoft) Source code hosting and CI/CD for VigilChain's own platform code; OIDC trust for keyless AWS deployments No customer data United States
PostHog, Inc. Product and marketing site analytics; JavaScript error capture Page views, events, user identifiers for logged-in users, IP-derived approximate location, JavaScript exceptions United States
Formspree, Inc. Marketing-site form processing (demo requests, contact form) Name, email, company, subject, and message content from form submissions United States
Google LLC Web fonts (Google Fonts) loaded at runtime on the marketing website IP addresses and user-agent strings, incidental to font delivery United States

Note on AI processing. Production AI inference for all tenants without their own Anthropic API key is served by Anthropic Claude through AWS Bedrock, hosted inside VigilChain's AWS environment. Under the AWS Bedrock service terms and Anthropic's Commercial Terms, your prompts and the model's responses are not used to train Claude or any other model and are not retained by Anthropic on this path. If you configure your own Anthropic API key (Bring Your Own AI Key), AI requests for your tenant are routed directly to your Anthropic account and are governed by your contractual relationship with Anthropic. See Section 10 for the full disclosure.

Other sharing

  • Legal requirements. We may disclose personal information if required by law, subpoena, court order, or governmental request, or when we believe in good faith that disclosure is necessary to investigate fraud, protect our rights, or protect the safety of you, us, or the public.
  • Business transfers. In connection with a merger, acquisition, financing, reorganization, or sale of all or a portion of our assets, personal information may be transferred. We will notify you of any such change in ownership or control.
  • With your consent. We may share your personal information with third parties when you have provided explicit consent or direction to do so.

We do not share personal information with advertisers, data brokers, or third parties for cross-context behavioral advertising.

5. International data transfers

VigilChain is based in the United States and processes data in AWS us-east-1 (N. Virginia). We do not currently transfer customer data outside the United States.

Our Services are currently offered to customers located in the United States. If you are located in the European Economic Area, the United Kingdom, or Switzerland and interact with the marketing website or communications, you understand and consent to the processing of your information in the United States. The United States may have different data protection standards than your country of residence.

If we expand our services to customers located in the European Economic Area, the United Kingdom, or Switzerland in the future, we will implement appropriate transfer mechanisms — such as the Standard Contractual Clauses approved by the European Commission — and update this Privacy Policy accordingly.

We do not currently claim participation in the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, or the Swiss-U.S. Data Privacy Framework.

6. How long we keep your information

We retain personal information for as long as it is necessary to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. Specific retention periods:

  • Source code submitted for scanning is retained only for the duration of the scan job, then purged from active storage. Metadata references (finding identifiers, file paths, line numbers) are retained for the life of the related finding.
  • Scan findings and associated metadata are retained for the life of your account. You may delete individual findings, assessments, or entire tenants from the Platform at any time.
  • Asset and infrastructure metadata is retained for the life of your account.
  • Account and platform user data is retained for the life of your account. Upon account closure, personal data is deleted within 60 days, consistent with Section 5.5(b) of the Standard Terms incorporated into our Terms of Service.
  • Security-relevant audit logs are retained for 7 years to support security investigation, dispute resolution, and compliance.
  • Operational and performance logs are retained for approximately 90 days, then aggregated or deleted.
  • Database backups are retained for 30 days.

Where retention is required by applicable law, or necessary to resolve disputes or enforce our agreements, we may retain certain information beyond these periods.

You may request deletion of your personal data at any time by contacting privacy@vigilchain.com. We complete deletion requests within 30 days and confirm in writing, subject to any lawful retention obligations that may apply.

7. How we protect your information

We implement technical and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration, and destruction:

  • Encryption in transit using TLS 1.2 or higher for all connections, with certificates managed by AWS Certificate Manager.
  • Encryption at rest using AWS KMS across the RDS database, S3 buckets, Secrets Manager, and log storage.
  • Row-level security at the PostgreSQL layer enforces tenant data isolation at the database engine itself, not by application code alone.
  • Passwords are stored as bcrypt hashes (12 rounds). Multi-factor authentication using time-based one-time passwords is available for all accounts.
  • Session and refresh tokens are stored in httpOnly, secure cookies that cannot be read by client-side JavaScript. The refresh-token cookie is path-restricted to the authentication refresh endpoint.
  • Access to your connected cloud environments uses read-only cross-account IAM roles. VigilChain cannot modify, create, or delete resources in your cloud.
  • Secrets and API keys are stored in AWS Secrets Manager, not in environment variables or source code.
  • All compute resources operate within private network subnets. Public-facing endpoints are protected by a web application firewall.
  • We maintain an information security program consistent with industry standards for business-to-business software-as-a-service.

While we strive to protect your personal information, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security, and we encourage you to protect your account credentials and to enable multi-factor authentication.

8. Your privacy rights

Depending on where you are located and how you interact with our Services, you may have the following rights regarding your personal information. We will not discriminate against you for exercising any of these rights.

For California residents (CCPA and CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we have collected about you, the categories of sources, the purposes for which we collected it, and the categories of third parties with whom we share it.
  • Delete personal information we have collected from you, subject to certain exceptions.
  • Correct inaccurate personal information we hold about you.
  • Opt out of sale or sharing. We do not sell your personal information and we do not share it for cross-context behavioral advertising. No opt-out action is required.
  • Limit use of sensitive personal information. We do not use sensitive personal information for purposes beyond those permitted by the CCPA.
  • Non-discrimination. We will not discriminate against you for exercising any of your privacy rights.

For residents of other US states

If you are a resident of Virginia, Colorado, Connecticut, Utah, Oregon, Texas, Montana, or another US state with a comprehensive privacy law, you have similar rights to those described above — including rights to access, delete, correct, and opt out of targeted advertising (which we do not conduct). The specific rights available depend on the applicable state law.

For individuals in the EEA, UK, or Switzerland

Although our Services are not currently offered to customers located in these regions, if we process your personal data incidentally (for example, because you visit our marketing website), you may have rights under the GDPR or equivalent laws, including the right to:

  • Access the personal data we hold about you;
  • Request rectification of inaccurate personal data;
  • Request erasure of your personal data;
  • Restrict or object to processing;
  • Receive your personal data in a portable format;
  • Withdraw consent for processing that is based on consent;
  • Lodge a complaint with your local data protection authority.

Our legal bases for processing personal data include the performance of a contract with you or your organization, our legitimate interests in operating and securing the Services, compliance with legal obligations, and your consent where required.

Data Processing Agreement

Customers who require a Data Processing Agreement to comply with the GDPR, UK GDPR, CCPA, or similar regulations may contact legal@vigilchain.com to request our DPA template.

How to exercise your rights

To exercise any of the rights described above, contact us at privacy@vigilchain.com. We will take reasonable steps to verify your identity before responding, and we will respond within the timeframe required by applicable law.

9. Cookies and tracking technologies

We take a minimal approach to cookies and tracking. A summary of what we use:

  • On app.vigilchain.com (the Platform): strictly necessary cookies only — vc_session, vc_refresh, and vc_csrf. These cookies are used for authentication and request-forgery protection. They are httpOnly, secure, and are not used to track your browsing activity.
  • On www.vigilchain.com (the marketing website): analytics cookies set by PostHog (ph_*_posthog) to understand how visitors use the site. These cookies store an anonymous device identifier; they do not track you across other websites.

We do not use advertising cookies, social media tracking pixels, or cookies for cross-site behavioral advertising.

For the complete list of cookies, their purposes, and how long they persist, see our Cookie Policy.

10. AI and machine learning

For a plain-language visual summary of what is sent to AI providers, in which call, and at what retention window, see Data Flow & AI Processing. The text below is the legally binding policy.

The Services use artificial intelligence models — Anthropic Claude served through Amazon Bedrock inside VigilChain's AWS environment by default — to classify security findings into a canonical taxonomy, confirm ambiguous deduplication decisions, analyze CI/CD configurations for deployment chain discovery, and generate finding narratives and remediation guidance.

When AI processing is applied to your data:

  • We send or make available the context needed for AI-assisted analysis. This may include rule identifiers, file paths, configuration snippets, finding metadata, and relevant source code from repositories cloned into VigilChain-controlled worker infrastructure for scan and analysis jobs. Credentials, secrets, database contents, service customer data, and known-sensitive data are not requested for AI analysis; we redact known-secret patterns before AI calls when detected.
  • AI processing occurs on your tenant's data in isolation. Your findings and content are never combined with another tenant's data before being sent to the AI provider.
  • AI outputs — classifications, narratives, risk scoring — are stored within your tenant and subject to the same access controls and row-level security as other Customer Content.

Our training commitment. VigilChain does not use Customer Content to train, fine-tune, or enhance artificial intelligence or machine learning models owned or operated by VigilChain, without your prior written consent. This commitment is reflected in the modification of Section 1.6 of the Common Paper Cloud Service Standard Terms contained in our Terms of Service.

Third-party AI training and retention. On the production AWS Bedrock path (default for all tenants without their own Anthropic API key), Anthropic does not use your prompts or responses to train Claude or any other model, and does not retain prompts or responses, per the AWS Bedrock service terms and Anthropic's Commercial Terms. AWS-side logging follows VigilChain's published retention policy and is governed by VigilChain's AWS account configuration. On the direct Anthropic API path (used only for tenants that have configured Bring Your Own AI Key, and for internal operator tooling), Anthropic's standard Commercial Terms apply: prompts may be retained by Anthropic for up to 30 days for trust-and-safety review and are not used for model training. Bring Your Own AI Key traffic is governed by your direct contractual relationship with Anthropic, not by VigilChain's. A Data Processing Agreement that reflects these flows is available on request at legal@vigilchain.com.

Limitations of AI outputs. AI-generated information may be incorrect, incomplete, or inaccurate. AI outputs are advisory and are not a substitute for qualified human review of security-critical decisions.

We may use Usage Data (how you and other users interact with the Platform) that has been aggregated and de-identified, such that it cannot reasonably be used to identify you, your organization, Users, or Customer Content, to maintain, improve, and promote our products and services.

11. Children's privacy

The Services are not intended for individuals under the age of eighteen (18). We do not knowingly collect personal information from anyone under 18. If you are under 18, you should not use the Services or provide personal information to us. If we learn that we have collected personal information from an individual under 18, we will delete that information promptly. If you believe an individual under 18 has provided personal information to us, please contact privacy@vigilchain.com.

12. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy at this URL with an updated effective date. For material changes that significantly affect how we process your personal information, we will provide additional notice by email or through the Services at least 30 days before the changes take effect. Your continued use of the Services after changes become effective constitutes acceptance of the updated policy.

13. Contact us

If you have questions about this Privacy Policy or our data practices, or to exercise your privacy rights:

VigilChain, Inc., a Delaware corporation.

Changelog

  • v1.0 — April 21, 2026. Initial publication. Replaces the earlier version dated March 27, 2026.