Sovereignty & compliance
Sovereignty is not a sales pitch: it is an architecture
Where is my data processed?
On your machines. The VIGIE agent decides locally and only sends behavioural events to the console, hosted on the infrastructure you choose — including fully on your own premises. We need no copy of your files to operate.
Our structure, stated plainly: VIGIE is published by SECUTOR PRO LLC, a US company (Lewes, DE), with contacts in France, the United Kingdom and Spain. That structure gives us a solid contractual framework, operational continuity and response capability across four countries. More importantly, it does not change your exposure: since analysis stays on your machines, we hold none of your data — no jurisdiction, ours included, can claim what we never received.
The test to run on any EDR vendor
"What is the exact list of fields your agent transmits, and how long do you keep them?" Our answer fits on one line: process path, hash, action, timestamp — stored on the infrastructure you choose. No file content, no document names.
Four verifiable guarantees
What you can verify yourself
Analysis never leaves the machine
The behavioural engine runs on the endpoint CPU. No suspicious file is uploaded, no document path is transmitted. The console only receives events: process, hash, action, timestamp.
We do not hold your data
This is the strongest guarantee available: data we never received cannot be resold, subpoenaed or leaked. Our company is American, our clients are European: the guarantee holds because it is architectural, not declarative.
Chained, verifiable evidence
Every incident, remediation action and assistant order is sealed with a SHA-256 hash linked to the previous one. Any deletion or edit breaks the chain and becomes visible.
Documents ready for NIS2 and GDPR
Timestamped incident file for the 24-hour early warning, detailed report within 72 hours, internal register and signed monthly audit report: the expected deliverables already exist.
Official texts and sources
Check our claims at the source
- ANSSI — cyber.gouv.fr
- CNIL — notification de violation
- Directive NIS2 (EUR-Lex)
- Cybermalveillance.gouv.fr
- MITRE ATT&CK
- CISA — Known Exploited Vulnerabilities