Skip to content
Vigil
Back to Vigil

Vigil Security

Legal

Vigil’s full suite of legal documents. For documents marked “Available on request”, contact operations@vigilsecurity.io.

  • End User Licence Agreement & SaaS Terms

    Governs use of the Vigil Security platform by subscribing customers and end users.

  • Privacy Policy

    How Vigil handles personal information. Aligned to the Privacy Act 1988 (Cth), GDPR, UK GDPR, and CCPA/CPRA where applicable.

  • Website Terms of Use

    Terms governing access to and use of vigilsecurity.io.

  • Cookie Policy

    How Vigil uses cookies and similar technologies on the Website.

  • Email Disclaimer

    Confidentiality and legal notices applying to email correspondence with Vigil.

  • Data Processing Addendum (DPA)

    Contractual data-processing terms for Customers handling personal information through the Platform.

  • Subprocessor Schedule

    List of third-party subprocessors used by Vigil to deliver the Platform.

Google API Services — Limited Use

Vigil's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The Vigil Report Phishing add-on accesses only the single email message a user explicitly chooses to report by clicking “Report Phishing.” That message is transmitted to Vigil's security backend solely to assess whether it is a real threat or a Vigil security-awareness simulation and to return a verdict to the reporting user and their organization's security team. Vigil does not use this data for advertising, does not sell it, and does not use it to train generalized AI or machine-learning models. No other messages in the mailbox are accessed, and nothing is read in the background.

Any automated analysis Vigil applies to a reported email, to help determine whether it is a genuine threat or a Vigil security-awareness simulation, is performed only by a self-hosted model that Vigil operates within its own isolated infrastructure in Australia. The reported message is processed locally within Vigil's environment, is never shared with any third-party AI or machine-learning provider, and is never used to train or improve any AI or machine-learning model.