Cybersecurity · Autonomous security VIs Vigil & Vendetta

Defend from within · Probe from without

Guard & hunt.

Two VIs working the same wall from opposite sides. Vigil watches from inside your systems and blocks attacks as they form. Vendetta attacks from outside — safely, on your behalf — finding the holes first and handing you the patch.

01 — Two sidesContinuous, not annual

A pentest once a year secures you for one day a year.

Attackers don't schedule. Vigil and Vendetta run without pause — one hardening from the inside, one stress-testing from the outside — so the gap between "vulnerable" and "patched" shrinks toward zero.

Coverage

24/7

Both VIs run continuously against your live surface.

Validation

PoC

Vendetta stops at proof — it demonstrates, it never detonates.

Control

Kill

A one-switch stop and full audit trail on every run.

Output

Fix

Every finding ships with a documented, prioritized patch.

02 — VigilDefensive · inside-out

Vigil lives inside the wall.

Given access to a system or architecture, Vigil builds a world model of it from within — every service, trust boundary, and data path — then works to keep attackers out before they get a foothold.

A

Scans from within to map the real attack surface.

Vigil enumerates your architecture from the inside: hosts, services, dependencies, identities, and the paths between them. It sees the misconfigurations and forgotten doors an outside scan never reaches.

That internal map is a world model — kept live as your infrastructure changes.

B

Learns normal, so it notices the moment something isn't.

By modelling ordinary behaviour — traffic, access patterns, process trees — Vigil spots the anomaly that signals an intrusion in progress, not just a signature it was handed.

Novel attacks look wrong before they're named. Vigil is built to feel that wrongness early.

C

Blocks proactively, within the guardrails you set.

When Vigil identifies an active threat it can act — isolate a host, revoke a token, tighten a rule — inside a policy you define. High-impact actions can require a human, or run autonomously where you've allowed it.

Speed where it's safe; a person in the loop where it counts.

D

Hardens continuously and reports what it changed.

Every vulnerability Vigil finds becomes a prioritized, documented fix, with a clear audit trail of what it did and why. Your posture improves a little every day instead of once a quarter.

Defence as a habit, not an event.

03 — VendettaOffensive · outside-in

Vendetta attacks you first.

From the outside, with nothing but what a real adversary would have, Vendetta probes your perimeter, chains what it finds, and proves the risk — then stops, documents it, and leaves the patch on your desk before anyone hostile arrives.

A

Enumerates the perimeter like an attacker, automatically.

Vendetta starts where a stranger starts: your externally exposed surface. It discovers assets you forgot you had, fingerprints them, and prioritizes the ones worth pushing on.

Ownership is verified first — Vendetta only tests what's yours.

B

Chains exploits step by step, each move built on a proven last one.

Real breaches are chains, not single bugs. Vendetta reasons across steps — a leak here enabling a foothold there — the way a skilled human red-teamer would, at machine breadth.

Rate-limited and scoped, so testing never becomes the incident.

C

Stops at proof. It demonstrates the risk; it never detonates it.

Vendetta halts at a non-destructive proof-of-concept — enough to show the path is real, never enough to cause harm. A kill switch and complete audit trail govern every run.

You get certainty about the danger without living through it.

D

Documents everything and hands Vigil the fix.

Each finding becomes a replayable evidence chain mapped to the frameworks you report against, plus a concrete remediation. Vendetta finds it; Vigil helps close it; a free retest confirms it's gone.

Offence and defence, feeding each other on a loop.

04 — Rules of engagementAutonomy with a leash

Powerful, and on a short chain.

R1

Authorized only

Vendetta verifies ownership before it touches an asset. It tests what you prove is yours, nothing else.

R2

Non-destructive

Validation stops at proof-of-concept. No data is exfiltrated, corrupted, or left changed.

R3

Kill switch

Every run is rate-limited, fully logged, and stoppable in one action, at any moment.

R4

Defensive by design

These are tools for the defender. We deploy them for organizations testing their own systems — not to enable attacks on anyone else.

Vigil and Vendetta are VIs: autonomous within strict scope, but never self-directed. They don't choose their own targets, can't act outside an authorized engagement, and keep a human accountable for every consequential decision.

05 — FAQCommon questions

Straight answers.

Will Vendetta break my production systems?
No. It's rate-limited, scoped to assets you've authorized, and stops at a non-destructive proof-of-concept. A kill switch halts any run instantly, and everything is logged.
How is this different from a scanner?
Scanners list known signatures. Vendetta reasons and chains — combining several low-severity findings into the real, high-severity path an attacker would actually take — and Vigil defends with a live world model of your system, not a static ruleset.
Do Vigil and Vendetta work together?
Yes. Vendetta finds and proves a weakness from outside; Vigil helps close it from inside; a free retest confirms the fix. Offence and defence on one loop.
Could these tools be misused to attack others?
They're built for defenders testing their own systems. Vendetta requires verified ownership of every target, engagements are contractual, and we don't operate them against third parties. Defensive purpose is designed in, not bolted on.
Are they autonomous?
Within a strict, authorized scope — yes. Beyond it — never. They don't pick their own targets or act outside an engagement, and a human stays accountable for consequential actions.