The security data platform for detection engineering and threat hunting

The detection and hunting stack you would build yourself. Already built. From $499 a month.

For startup security teams on AWS: your logs land as tables in a dedicated AWS account, every detection is a KQL-compatible query that can join any of them, and every hunt runs over your whole history. SSO, SCIM, required MFA, customer-managed keys and a queryable audit trail come with every plan — the features your auditor and your biggest customer ask about, without the enterprise price or a data engineer to run it.

One AWS account per customer

the lake, the query engine, the keys and the user pool — all inside it, none shared

Every enterprise feature on every plan

SSO, SCIM, required MFA, customer-managed keys and the audit trail on Startup — not an upsell

Pauses at the cap, never bills past it

a feed that hits its ceiling waits at the source until you top up — nothing dropped, nothing invoiced

Why startups choose it

Enterprise-grade security operations, sized for a team of one to five.

A startup security team has the same adversaries as a large one, the same audit, and the same customers asking the same questions — with a fraction of the people and budget. Vigilfield is built for exactly that gap.

You are the security team, not the data team

A SIEM you build yourself on Athena or OpenSearch becomes the job: pipelines, parsers, partitions, a bill to watch. Vigilfield is that system already built and run for you. You deploy one CloudFormation stack, and your logs arrive as tables you can query that afternoon.

The auditor wants evidence, not screenshots

SOC 2 and ISO 27001 ask for log retention, access control and a record of who did what. Retention is set per table, access is teams and permissions behind your SSO, and every action in the workspace is written to an audit table you can query and hand over.

Your biggest customer sent a security questionnaire

Where does our data live? Who can reach it? Can we hold the keys? Is MFA enforced? A dedicated AWS account per customer, customer-managed KMS keys, SSO, SCIM and required MFA — with passkeys and FIDO2 security keys — are the answers, and they come with the $499 plan, not the enterprise tier.

Product

Logs in. Detections over them. Hunts across them.

Most detection tools are a pattern matcher over a stream, with correlation bolted on. Vigilfield is a query engine over tables, where every result is another table — so joins, baselines and chained detections are the normal case, not a roadmap item.

Ingest in an afternoon

One CloudFormation stack grants a read-only role, and Vigilfield wires the S3 notifications itself. CloudWatch Logs need a log group ARN and one permission. Many accounts? Vigilfield generates the IAM templates for all of them in one step. No Kinesis, Firehose or Lambda of yours to run.

Normalized on arrival

CloudTrail, VPC Flow Logs, Route 53 resolver logs, S3 access logs and GuardDuty findings land as OCSF tables. Anything else — including HTTP APIs we pull on a schedule — gets a schema and a VRL extractor you control.

Detection engineering that composes

A detection is a scheduled VFQL query that can join CloudTrail to flow logs to DNS in one statement. Its findings are a table, so the next detection can read them: allowlists, baselines and rollups instead of tuning tickets. Every run is recorded, and a failing rule tells you.

Threat hunting over your whole history

Hunt in the language your detections use, over every month you keep — not a 90-day window. Query any table as it was at an earlier version, save the trail as an investigation, and promote the hunt that worked into a scheduled detection.

Alerts your on-call can work

Detections raise alerts you acknowledge and resolve in one list, and send them to your SNS topic so they reach whatever your on-call already uses. Vigilfield also alerts on itself: a source that goes quiet, a rule that fails, a plan nearing its ceiling.

A query language you already know

VFQL is KQL-compatible — filter, join, project, summarize, left to right — and the editor checks each query as you type. If your team has written Sentinel or Defender queries, they can write a Vigilfield detection today.

What $499 a month gets you

Everything. On the Startup plan.

No feature tiers, no add-ons, no per-seat pricing. Every plan includes all of this; the plans differ only by how much data they carry.

Detection & response

  • Scheduled detections in VFQL, joins included
  • Detections that read other detections’ findings
  • Alert list with acknowledge and resolve
  • Alerts to your SNS topic
  • Run history for every rule

Threat hunting

  • KQL-compatible query language
  • Hunts over your full retained history
  • Time travel to earlier table versions
  • Investigations and folders your team shares
  • Export any result to your own S3

Data you own

  • OCSF tables for five AWS log types
  • Custom sources, schemas and extractors
  • Apache Iceberg in your dedicated account
  • Retention you set per table
  • Export everything, any time

Enterprise controls

  • A dedicated AWS account, never shared
  • SSO (SAML and OIDC) and SCIM
  • Required MFA: authenticator apps, passkeys, FIDO2 keys
  • Customer-managed KMS keys
  • Teams with fine-grained permissions
  • A queryable audit trail of every action

Operations we run

  • Provisioning, upgrades and scaling
  • Source health: freshness checks and replay
  • Alerts at 80% and 100% of your plan
  • No overage bill, ever
  • Onboarding: we write your first detections with you

Built to connect

  • A documented API for every action
  • Scoped credentials for apps and agents
  • IAM templates for all your accounts in one step
  • Open Iceberg: Athena, Spark or DuckDB
  • Email support on every plan
Isolation

A dedicated account. Your keys. Your format.

Every customer gets a dedicated AWS account with its own S3 lake, its own query engine, its own KMS key — or one you manage — and its own user pool. Tenant isolation is an account boundary, not a filter clause. The tables are Apache Iceberg, readable by Athena, Spark or DuckDB without asking us, and they leave with you when you say so.

Apache Iceberg on S3Per-table retentionSSO (SAML and OIDC)SCIM provisioningRequired MFA, passkeys and security keysA dedicated AWS accountCustomer-managed KMS keysTeams and fine-grained permissionsA queryable audit trailScoped API tokensExport to your own S3
01

Connect — day one

We provision your dedicated AWS account. You deploy one CloudFormation stack, or paste a log group ARN. Logs start flowing and land as OCSF tables.

02

Detect — week one

We write your first detections with you, joined across CloudTrail, flow logs, DNS and your own sources. Findings become tables; alerts go to SNS.

03

Hunt — from then on

Pivot from a finding to the raw events in the same language, over your whole history, and save the trail as an investigation your auditor can read.

Pricing

Every plan is the enterprise plan. The difference is volume.

Prepaid and predictable. When a meter reaches its ceiling, that source pauses — loudly, with an alert at 80% and at 100% — and your logs wait in your own bucket or log group until you buy a top-up pack (100 GB ingested for $75) or the month rolls over. Nothing is dropped, and nothing is billed that you did not pay for first.

Startup

$499 per month

Billed yearly, $5,988

Sized for a small team’s first AWS footprint.

  • 200 GB ingested per month
  • 1 TB scanned per month
  • 600 GB stored
  • Email support
  • Everything on this page — every feature, unlimited users and detections

SMB

$1,499 per month

Billed yearly, $17,988

Sized for multi-account environments.

  • 3 TB ingested per month
  • 15 TB scanned per month
  • 9 TB stored
  • Email support, one business day
  • Everything on this page — every feature, unlimited users and detections

Enterprise

Contact us

Priced to your volume and terms

Sized for organization-wide coverage.

  • 10 TB and up ingested per month
  • 50 TB scanned per month
  • 30 TB stored
  • Dedicated support and an SLA
  • Everything on this page — every feature, unlimited users and detections
Talk to sales
Questions

What startup security teams ask us first.

We are a security team of two. Can we run this?

That is who it is built for. We provision and operate the platform; you deploy one stack per AWS account, and we write your first detections with you. There is no pipeline, cluster or parser of yours to keep alive.

What happens if a log source spikes?

You get an alert at 80% and at 100% of your plan. At the ceiling that source pauses and its logs wait in your own bucket or log group — nothing is dropped. Buy a top-up pack or wait for the month to roll over, and it catches up. You never get a bill you did not agree to first.

Will this help with SOC 2?

It covers the logging and monitoring evidence auditors ask for: retention you set per table, access control through your SSO, detections with run history, and an audit table of every action in the workspace. Vigilfield does not make you compliant on its own, but it answers the log-management questions.

Where does our data live, and can we leave?

In a dedicated AWS account that holds only your organization, encrypted with a Vigilfield-managed key or one you manage. The tables are Apache Iceberg, readable by Athena, Spark or DuckDB, and you can export everything to your own S3 whenever you like.

We only run on AWS. Is that a problem?

That is the point. Vigilfield is built for AWS first: CloudTrail, VPC Flow Logs, Route 53, S3 access logs and GuardDuty are normalized out of the box, and anything else you can reach over S3, CloudWatch Logs or an HTTP API becomes a table with a schema you define.

Is there a limit on users or detections?

No. Plans are sized by data volume — ingested, scanned and stored — not by seats, rules or features. Add your whole team and write as many detections as you need.

Talk to us

Bring a bucket of logs and the detection your current tool cannot express.

In a 30-minute walkthrough we will show your team the platform and scope your first detections. Onboarding is a conversation, not a signup form: we provision your dedicated account, you deploy one stack, and we write the first detections together.