CSPM · CVE Scanning · Compliance

Security posture you can actually prove.

Iron Vigil continuously scans your images, cloud, and endpoints for vulnerabilities and misconfigurations — then maps the findings to the compliance frameworks your auditors care about.

Everything you need to stay secure & compliant

Scan

CVE & vulnerability scanning

Grype-powered scanning of container images and dependencies — severity, CVSS, and the version that fixes it.

Cloud

Cloud posture (CSPM)

Assume-role into AWS, Azure & GCP and surface misconfigurations against best-practice baselines.

Comply

Compliance automation

SOC 2, HIPAA, PCI-DSS, ISO 27001, CIS and more — findings mapped to controls and scored over time.

Evidence

Audit evidence, collected

Automatic, agent, and guided evidence collection with a read-only, time-limited auditor portal.

Agent

Lightweight endpoint agent

A cross-platform agent for endpoint posture and evidence, enrolled with auto-expiring tokens.

Integrate

Fits your stack

GitHub, Slack, Jira, SIEM and a public CI security-scan action — wire Iron Vigil into the workflow you already have.

How it works

1

Connect

Sign in and connect a repo, image, cloud account, or endpoint. Multi-tenant from day one.

2

Scan

Continuous CVE, cloud-posture, and compliance scans run against everything you connect.

3

Prove

Watch your security score and per-framework compliance posture climb as you remediate.

Simple, scaling pricing

PricingComing SoonPlans & pricing are being finalized.

Find what's exposed. Prove what's compliant.

Get started free