Security

Endpoint security at enterprise grade

Protect your company data with the same technology used by banks and financial institutions. From the agent installed on the device to the last record in the database, everything goes through layers of protection.

AES-256

Data at rest

TLS 1.3

Data in transit

ISO 27001

Aligned controls

99.9%

Availability

Encrypted the whole way

Every payload the agent sends is signed and encrypted. Nothing travels in plain text between the device and the platform.

The key belongs to your company

Dual-key encryption: without the half that stays with you, the collected data cannot be read — not even by us.

Compliant from day one

Controls aligned with ISO 27001 and compliance with GDPR and LGPD, with an audit trail for every action.

Encryption

End-to-end encryption, anywhere in the world

Every monitored device talks to the platform over an encrypted channel it opens itself. Wherever the team is, the data path is the same.

Encrypted in transit

Every payload goes out over TLS 1.3 with an HMAC signature. The agent is always the one opening the connection — no open port on your network.

Encrypted at rest, with a dual key

Records land encrypted with AES-256 and only open with both halves of the key. One of them stays with your company.

The same protection in every region

Wherever your team works the data path is identical — and compliance follows the data protection law in force in each country of operation.

Architecture

The data path, end to end

From the monitored device to the manager dashboard, data goes through four stages — and it is never exposed in any of them.

1

Agent on the device

Collects only what the company policy allows and signs every payload it sends.

2

Encrypted channel

TLS 1.3 outbound, always started by the agent — no open port on your network.

3

Platform

The signature is checked on every request; whatever does not match is dropped at the door.

4

Storage

Records encrypted with AES-256 and isolated per company, with a retention window you define.

TLS 1.3 · HMAC signatureRequest without a valid signature: dropped before it reaches the data

Protection

Protection on several fronts

Encryption is only the beginning. Day-to-day security rests on the controls your team uses inside the platform.

Role-based access control

Role-based permissions (RBAC): each person sees only the devices and metrics within their scope.

Dual-key encryption

One half of the key stays with Vigilioo, the other with your company. Without both, the data cannot be read.

Audit trail

Who accessed it, what they changed and when. Every action on the platform becomes a searchable record.

Device policies

USB ports, Bluetooth and remote lock applied by policy, device by device.

Compliance

Compliance your legal team will recognize

Monitoring the operation and respecting the privacy of the people in it are not opposites — the platform was designed for both.

ISO 27001

Aligned controls

Access management, incident logging and periodic reviews following the controls in the standard.

LGPD

Fully compliant

Legal basis, stated purpose, configurable retention and permanent deletion on request.

GDPR

Fully compliant

Data subject rights, a legal basis for international transfers and a record of processing activities.

Vigilioo runs for operations in several countries. Controls follow the data protection law in force in each region where your team works.

Controls at every layer

What holds the platform together at each stage, from the monitored device to the database.

Device

  • Agent signed and verified at install time
  • Collection limited by company policy
  • USB port and Bluetooth blocking
  • Remote device lock

Transport

  • TLS 1.3 on every connection
  • Connection always started by the agent
  • HMAC signature on every payload
  • Certificates renewed automatically

Platform

  • Role-based access control (RBAC)
  • Sessions with expiry and instant revocation
  • Per-company data isolation
  • Audit trail for every action

Data

  • AES-256 encryption at rest
  • Dual key, one half with you
  • Retention defined by policy
  • Permanent deletion on request

Need the documentation for your security team?

We send the technical breakdown of the controls, the data flow and the data processing agreement template for your compliance team to review.

Request documentation

Ready to monitor your team with precision?

Start for free today. No credit card required. Set up in less than 5 minutes.

7-day free trial
No credit card
Cancel anytime
Real-time screen monitoringUSB and Bluetooth port lockdownShift control with automatic time trackingSites and programs allowed by policyLocation and geographic boundariesPrecautionary device lockTeam productivity reportsEnd-to-end AES-256 encryptionReal-time screen monitoringUSB and Bluetooth port lockdownShift control with automatic time trackingSites and programs allowed by policyLocation and geographic boundariesPrecautionary device lockTeam productivity reportsEnd-to-end AES-256 encryption