One AWS account per customer
the lake, the query engine, the keys and the user pool — all inside it, none shared
For startup security teams on AWS: your logs land as tables in a dedicated AWS account, every detection is a KQL-compatible query that can join any of them, and every hunt runs over your whole history. SSO, SCIM, required MFA, customer-managed keys and a queryable audit trail come with every plan — the features your auditor and your biggest customer ask about, without the enterprise price or a data engineer to run it.
One AWS account per customer
the lake, the query engine, the keys and the user pool — all inside it, none shared
Every enterprise feature on every plan
SSO, SCIM, required MFA, customer-managed keys and the audit trail on Startup — not an upsell
Pauses at the cap, never bills past it
a feed that hits its ceiling waits at the source until you top up — nothing dropped, nothing invoiced
A startup security team has the same adversaries as a large one, the same audit, and the same customers asking the same questions — with a fraction of the people and budget. Vigilfield is built for exactly that gap.
A SIEM you build yourself on Athena or OpenSearch becomes the job: pipelines, parsers, partitions, a bill to watch. Vigilfield is that system already built and run for you. You deploy one CloudFormation stack, and your logs arrive as tables you can query that afternoon.
SOC 2 and ISO 27001 ask for log retention, access control and a record of who did what. Retention is set per table, access is teams and permissions behind your SSO, and every action in the workspace is written to an audit table you can query and hand over.
Where does our data live? Who can reach it? Can we hold the keys? Is MFA enforced? A dedicated AWS account per customer, customer-managed KMS keys, SSO, SCIM and required MFA — with passkeys and FIDO2 security keys — are the answers, and they come with the $499 plan, not the enterprise tier.
Most detection tools are a pattern matcher over a stream, with correlation bolted on. Vigilfield is a query engine over tables, where every result is another table — so joins, baselines and chained detections are the normal case, not a roadmap item.
One CloudFormation stack grants a read-only role, and Vigilfield wires the S3 notifications itself. CloudWatch Logs need a log group ARN and one permission. Many accounts? Vigilfield generates the IAM templates for all of them in one step. No Kinesis, Firehose or Lambda of yours to run.
CloudTrail, VPC Flow Logs, Route 53 resolver logs, S3 access logs and GuardDuty findings land as OCSF tables. Anything else — including HTTP APIs we pull on a schedule — gets a schema and a VRL extractor you control.
A detection is a scheduled VFQL query that can join CloudTrail to flow logs to DNS in one statement. Its findings are a table, so the next detection can read them: allowlists, baselines and rollups instead of tuning tickets. Every run is recorded, and a failing rule tells you.
Hunt in the language your detections use, over every month you keep — not a 90-day window. Query any table as it was at an earlier version, save the trail as an investigation, and promote the hunt that worked into a scheduled detection.
Detections raise alerts you acknowledge and resolve in one list, and send them to your SNS topic so they reach whatever your on-call already uses. Vigilfield also alerts on itself: a source that goes quiet, a rule that fails, a plan nearing its ceiling.
VFQL is KQL-compatible — filter, join, project, summarize, left to right — and the editor checks each query as you type. If your team has written Sentinel or Defender queries, they can write a Vigilfield detection today.
No feature tiers, no add-ons, no per-seat pricing. Every plan includes all of this; the plans differ only by how much data they carry.
Every customer gets a dedicated AWS account with its own S3 lake, its own query engine, its own KMS key — or one you manage — and its own user pool. Tenant isolation is an account boundary, not a filter clause. The tables are Apache Iceberg, readable by Athena, Spark or DuckDB without asking us, and they leave with you when you say so.
We provision your dedicated AWS account. You deploy one CloudFormation stack, or paste a log group ARN. Logs start flowing and land as OCSF tables.
We write your first detections with you, joined across CloudTrail, flow logs, DNS and your own sources. Findings become tables; alerts go to SNS.
Pivot from a finding to the raw events in the same language, over your whole history, and save the trail as an investigation your auditor can read.
Prepaid and predictable. When a meter reaches its ceiling, that source pauses — loudly, with an alert at 80% and at 100% — and your logs wait in your own bucket or log group until you buy a top-up pack (100 GB ingested for $75) or the month rolls over. Nothing is dropped, and nothing is billed that you did not pay for first.
$499 per month
Billed yearly, $5,988
Sized for a small team’s first AWS footprint.
$1,499 per month
Billed yearly, $17,988
Sized for multi-account environments.
Contact us
Priced to your volume and terms
Sized for organization-wide coverage.
That is who it is built for. We provision and operate the platform; you deploy one stack per AWS account, and we write your first detections with you. There is no pipeline, cluster or parser of yours to keep alive.
You get an alert at 80% and at 100% of your plan. At the ceiling that source pauses and its logs wait in your own bucket or log group — nothing is dropped. Buy a top-up pack or wait for the month to roll over, and it catches up. You never get a bill you did not agree to first.
It covers the logging and monitoring evidence auditors ask for: retention you set per table, access control through your SSO, detections with run history, and an audit table of every action in the workspace. Vigilfield does not make you compliant on its own, but it answers the log-management questions.
In a dedicated AWS account that holds only your organization, encrypted with a Vigilfield-managed key or one you manage. The tables are Apache Iceberg, readable by Athena, Spark or DuckDB, and you can export everything to your own S3 whenever you like.
That is the point. Vigilfield is built for AWS first: CloudTrail, VPC Flow Logs, Route 53, S3 access logs and GuardDuty are normalized out of the box, and anything else you can reach over S3, CloudWatch Logs or an HTTP API becomes a table with a schema you define.
No. Plans are sized by data volume — ingested, scanned and stored — not by seats, rules or features. Add your whole team and write as many detections as you need.
In a 30-minute walkthrough we will show your team the platform and scope your first detections. Onboarding is a conversation, not a signup form: we provision your dedicated account, you deploy one stack, and we write the first detections together.