Trust

Built to run inside your boundary

How we handle your data, how we secure what we ship, how the open source project is governed, and how to report a vulnerability.

Data handling

Nothing leaves in production

DeepTempo deploys only in customer environments: on premises, fully air-gapped, inside your data lake, or in your own cloud or Kubernetes. There is no hosted or managed tier, so there is no DeepTempo copy of your telemetry to breach.

Production

Telemetry, model weights, embeddings, and findings stay inside your boundary.

Assessment by sample

Only if you choose it: transferred under an evaluation agreement, processed in an isolated environment, and deleted when the assessment closes.

Assessment on premises

Nothing leaves, from the first day.

Language models

Vigil uses the model you choose. A local model keeps every request on your hardware; a hosted model receives only what you route to it.

Software supply chain

What we ship, and how you verify it

Signed releases

Vigil release images are signed keyless through the project's release workflow and verifiable with cosign against a pinned identity.

Secure defaults

Authentication is on from first start. No default credentials ship, and the first administrator account is created by you.

Vigil Assured

For production: reproducible builds with SBOM and provenance, validated deployment profiles, patch SLAs, and a release evidence pack. Control-enabling and evidence-producing for regulated environments.

Least privilege for agents

Workflows declare the tools each phase may use, containment requires approval below your confidence bar, and Vigil prefers the least powerful agent that can complete a step.

Open source governance

Apache 2.0, and not open core

Vigil is fully open source under the Apache License 2.0. Features are not withheld from the open project to sell a commercial edition. Customer-only software, such as licensing, richer reporting, and remote support enablement, sits beside Vigil rather than inside it.

The project accepts contributions on GitHub, publishes its versioning and security policies in the repository, and documents its contracts so integrations can depend on them.

License

Apache 2.0, with the full text in the repository.

Contributions

Issues and pull requests at github.com/Vigil-SOC/vigil.

Community

Documentation, office hours, and discussion at vigilsoc.org.

Alliances

DeepTempo is a member of the Open Secure AI Alliance, hosted by the Linux Foundation.

Vulnerability disclosure

Report a vulnerability

Please report security issues privately, and do not open a public issue, pull request, or discussion. We acknowledge reports promptly and coordinate disclosure so operators can patch before details are public.

For Vigil

Use GitHub private vulnerability reporting at github.com/Vigil-SOC/vigil/security/advisories/new. It is the fastest path and lets us credit you and request a CVE in one step.

For anything else

Email security@deeptempo.ai, including for this website, LogLM, or a report you cannot file on GitHub. If you need to encrypt, say so in a first message without technical detail and we will reply with a key.

What to include

The impact, the affected version or commit, and the steps to reproduce. A report we can reproduce is one we can fix in days rather than weeks.

Machine-readable policy

Vigil publishes an RFC 9116 policy at vigilsoc.org/.well-known/security.txt, and the full policy is in the repository's SECURITY.md.