Security and Compliance
Submissions are securely ingested, structured, and retained within established security and compliance frameworks. The platform applies encryption in transit and at rest, role-based access control, comprehensive audit logging, and controlled workflows. Every interaction leaves a traceable record.
VIGILITI is SOC 2 Type II attested and aligned with NIST 800-53 controls. It is designed for deployment in GovCloud and FedRAMP-aligned environments and is built for CJIS-compatible public safety use cases.
Framework Alignment
Public sector deployments align with NSI, BTAM, and 28 CFR Part 23 requirements for pre-investigative intake. Enterprise deployments align with Sarbanes-Oxley (SOX) Section 803, NIST 800-53, and SOC 2 Trust Service Criteria.
Privacy and Governance
VIGILITI structures information upstream for downstream review of investigation and analysis, preserving context without premature interpretation or escalation. Organizational control over evaluation, retention, and dissemination is maintained throughout.
The platform enforces a clean separation between the information intake layer and investigative or compliance processes. Sensitive and unverified information is handled appropriately, with configurable retention and lifecycle controls aligned to agency and organizational policy.
Controls at a Glance
Access Control
Role-based access and least-privilege enforcement ensure that individuals access only what their role requires. Permissions are configurable.
Data Protection
Encryption in transit and at rest, controlled data handling practices, and configurable retention policies protect sensitive submissions throughout their lifecycle.
System Integrity
Structured workflows and change traceability maintain the integrity of information from submission through disposition. The system supports governance-aligned record management across both public and private sector deployments.
Capabilities and Control
VIGILITI is designed to structure information at intake while enabling organizations to apply their own policies for evaluation, retention, and dissemination. Configurable audit controls and role-based access align with record management requirements across law enforcement, fusion center, and regulated enterprise environments.
For questions about VIGILITI’S privacy practices or security questions, contact:

