Built to run inside your boundary
How we handle your data, how we secure what we ship, how the open source project is governed, and how to report a vulnerability.
Nothing leaves in production
DeepTempo deploys only in customer environments: on premises, fully air-gapped, inside your data lake, or in your own cloud or Kubernetes. There is no hosted or managed tier, so there is no DeepTempo copy of your telemetry to breach.
Telemetry, model weights, embeddings, and findings stay inside your boundary.
Only if you choose it: transferred under an evaluation agreement, processed in an isolated environment, and deleted when the assessment closes.
Nothing leaves, from the first day.
Vigil uses the model you choose. A local model keeps every request on your hardware; a hosted model receives only what you route to it.
What we ship, and how you verify it
Signed releases
Vigil release images are signed keyless through the project's release workflow and verifiable with cosign against a pinned identity.
Secure defaults
Authentication is on from first start. No default credentials ship, and the first administrator account is created by you.
Vigil Assured
For production: reproducible builds with SBOM and provenance, validated deployment profiles, patch SLAs, and a release evidence pack. Control-enabling and evidence-producing for regulated environments.
Least privilege for agents
Workflows declare the tools each phase may use, containment requires approval below your confidence bar, and Vigil prefers the least powerful agent that can complete a step.
Apache 2.0, and not open core
Vigil is fully open source under the Apache License 2.0. Features are not withheld from the open project to sell a commercial edition. Customer-only software, such as licensing, richer reporting, and remote support enablement, sits beside Vigil rather than inside it.
The project accepts contributions on GitHub, publishes its versioning and security policies in the repository, and documents its contracts so integrations can depend on them.
Apache 2.0, with the full text in the repository.
Issues and pull requests at github.com/Vigil-SOC/vigil.
Documentation, office hours, and discussion at vigilsoc.org.
DeepTempo is a member of the Open Secure AI Alliance, hosted by the Linux Foundation.
Report a vulnerability
Please report security issues privately, and do not open a public issue, pull request, or discussion. We acknowledge reports promptly and coordinate disclosure so operators can patch before details are public.
For Vigil
Use GitHub private vulnerability reporting at github.com/Vigil-SOC/vigil/security/advisories/new. It is the fastest path and lets us credit you and request a CVE in one step.
For anything else
Email security@deeptempo.ai, including for this website, LogLM, or a report you cannot file on GitHub. If you need to encrypt, say so in a first message without technical detail and we will reply with a key.
What to include
The impact, the affected version or commit, and the steps to reproduce. A report we can reproduce is one we can fix in days rather than weeks.
Machine-readable policy
Vigil publishes an RFC 9116 policy at vigilsoc.org/.well-known/security.txt, and the full policy is in the repository's SECURITY.md.
