Expose the attacker before the attacker exposes you.
Deploy credible decoys across your infrastructure and turn every interaction into a high-confidence signal. No legitimate process has a reason to touch them — so the first touch is, by definition, an intruder.
Less noise. More certainty.
The perimeter falls. The question is how fast you find out.
Behaviour-based detection produces noise
Signatures and heuristics generate thousands of alerts per day. The SOC triages the noisiest ones, not the most important.
Lateral movement looks like administration
An attacker who has stolen valid credentials does exactly what an admin does. There is no anomaly to detect.
Dwell time is measured in weeks
Not because the attack is subtle, but because nothing in the network was placed there specifically to be touched by mistake.
Plant. Wait. Know.
Plant
Decoys are generated for your specific environment — your naming conventions, your stack, your topology. Not an identical template for every client.
Wait
Decoys do nothing. They don’t scan, don’t block and don’t interfere with production. They sit. High-confidence signals don’t come from an accuracy promise but from the fact that nothing legitimate has a reason to touch them.
Know
A touch becomes an incident with a complete narrative: the compromised host the identity came from, the destination touched, the pivot point. Not a log line — a chain.
Under the hood
The same principles, applied to every surface an attacker moves across.
01Lateral-movement detection with attribution
Not just "someone tried to authenticate." Which host was compromised, where the attacker went and what path they took.
02Decoys beyond files
Credentials, saved sessions, browser entries, identity artefacts — the surfaces an attacker actually looks for after gaining access.
03Cloud deception, no agents
Real but powerless trap keys in your own account. Their use shows up in the provider’s own audit feed. Zero binaries to install, zero EDR exceptions.
Validated live on AWS. Detection within minutes of use.04Active Directory & Kerberos
Decoy service accounts that are never used legitimately. Any ticket request for them is hostile reconnaissance, collected off-host.
05Network layer and DNS
Phantom hosts and names that don’t exist for anyone other than whoever is looking for them. The platform never becomes your resolver.
06Non-intrusion as an invariant
Three prohibitions enforced programmatically on every placement: don’t overwrite anything, don’t place on active paths, don’t enter the user’s working layer. A security sensor that breaks production is not a security sensor.
07Every deployment is different
Nothing observable is fixed between installations. There is no global signature an attacker can study once and bypass across all our clients.
08Real air gap
Models run locally, on-prem. No information about your topology or naming leaves the network. For classified environments this isn’t a feature — it’s the entry condition.
09Integrates, doesn’t replace
Standard-format SIEM export, notifications on the channels your team already uses. Vigilum sits beside your EDR, not in place of it.
10Console in your team’s language
Multilingual interface and alerts built in from the start, including Romanian. Not a translation tacked on at the end.
Built by people who break in, for people who defend
15 years of penetration testing and red teaming in defence, government and critical infrastructure. Vigilum is the product of those 15 years of watching how attackers move inside.
DNSC authorised. Known supplier in Romania’s defence sector.
Runs in your rack. Your data stays yours — including fully disconnected.
We don’t leave you alone at install. Environment characterisation is the difference between deception that catches and theatre; we do it with you.
Limited seats, in production, before general release
We’re opening a limited number of seats for organisations that want to deploy Vigilum in production before the general release — and help shape what it looks like at launch.
What you get
- Deployment assisted by the team that built the platform, including environment characterisation.
- Direct line to engineers. What you ask enters the roadmap or you learn why not.
- A production pilot before full deployment.
- Commercial terms discussed directly, based on your environment and needs.
What we ask in return
- Structured feedback during the pilot.
- An open communication channel with your technical team.
- A public reference only if and when you choose. It’s not a condition.
Who qualifies
- Defence, defence industry, public administration, energy and utilities, healthcare, financial — or any organisation with NIS2-type requirements.
- A real production environment, not just a lab.
- A designated technical contact on your side for the duration of the pilot.
Tell us what you want to detect
We’ll respond within two business days. No marketing list — your data is used solely for evaluating the Early Access request.
What technical teams ask us
Does it interfere with production?
No. Decoys are not placed on active paths, don’t overwrite anything and don’t enter what users use daily. This is a rule enforced by the platform, not a good intention.
What happens with our EDR?
It stays. Vigilum is complementary. For certain decoy classes you’ll add an exception on your EDR — we’ll guide you through it.
We don’t use cloud. Is it relevant?
Yes. A trap key in your own account works even if the rest of your infrastructure is fully on-prem — an attacker can’t verify whether it’s real without using it, and the use is the detection.
What data leaves our network?
In the on-prem configuration, none. A fully disconnected variant is available for classified environments.
Is it open source?
No. The platform is commercial, delivered and configured by SafeByte.
How long does installation take?
The installation itself takes under an hour. Custom configuration, depending on your infrastructure, usually takes longer.