Vercel breach — Apr 19, 2026 — customer env vars & API keys exposed. Are you affected?

Your stack got breached.
Did you know?

Vigil monitors security alerts, CVEs, and breach disclosures across your entire SaaS stack — and alerts you the moment something real happens. Every alert is verified from multiple sources before it reaches your inbox. No gossip, no noise.

No credit card required. Cancel anytime.

Recent alerts
Live pipeline · 3 verified
criticalBREACH

VercelSupply chain breach via Context.ai OAuth

Apr 19, 2026
criticalCVE-2025-30066CVE

GitHubtj-actions/changed-files compromised

Mar 14–15, 2025
highCVE-2024-10978CVE

PostgreSQLNon-owner statement execution privilege escalation

Nov 14, 2024

How it works

01

Register your stack

Select the SaaS tools and services your team depends on — Vercel, Stripe, Supabase, GitHub, and 20+ others.

02

We monitor continuously

Our pipeline polls CISA KEV, GitHub Advisories, and vendor security feeds every 30 minutes.

03

You get a verified alert

We only send you alerts that are corroborated from 2+ sources. Critical CVEs hit your inbox within 60 minutes of verification.

Data sources

Three verified sources. One inbox.

CISA KEV

Known exploited vulnerabilities, confirmed by CISA

GitHub Advisory DB

npm, pip, Go, Rust ecosystems

Vendor RSS Feeds

Direct from Vercel, AWS, Stripe & more

Every CVE alert requires corroboration from at least 2 sources before it reaches you. CISA KEV entries are sent immediately — they're confirmed exploited.

Trusted by developers using

VercelSupabaseRailwayStripeCloudflareGitHubAWSMongoDBClerkResendNeonPlanetScale

+20 more tools monitored

The clock starts the moment you know.

When Vigil detects a breach in software your organisation runs, you know within 60 minutes. Faster awareness means more time to assess scope, involve counsel, and prepare before regulatory windows close.

EU GDPR — Article 33(1)

Regulation (EU) 2016/679

European Union
72 hoursfrom becoming aware of a breach

Vigil surfaces breaches across your SaaS stack within 60 minutes of detection — giving you over 71 hours of your regulatory window to assess scope, involve counsel, and prepare your supervisory authority notification.

UK GDPR — ICO Requirement

UK Data Protection Act 2018

United Kingdom
72 hoursfrom becoming aware of a breach

The UK post-Brexit framework mirrors the EU 72-hour clock. If your stack spans both UK and EU data subjects, a single Vigil alert gives your team simultaneous awareness — maximising response time under both frameworks.

SEC Cybersecurity Disclosure Rule

17 CFR §229.106 (Item 1.05 of Form 8-K)

United States (public companies)
4 business daysfrom determination of materiality

For public companies, the SEC clock starts at "determination of materiality" — not awareness. Vigil's rapid detection gives security teams more time to assess materiality before the mandatory disclosure window opens.

Notifiable Data Breaches Scheme

Privacy Act 1988 (Cth), Part IIIC

Australia
30 daysfrom becoming aware (OAIC guidance)

Australia's NDB scheme requires notification once a breach is assessed as "eligible." Vigil accelerates the awareness phase — the prerequisite for starting your formal assessment.

Vigil is an informational alerting service, not a legal compliance tool. Regulatory obligations vary by jurisdiction, data type, and organisational context. Consult qualified legal counsel for breach response obligations.

Pricing

Simple pricing. No sales call required.

7-day free trial on all plans. Cancel at any time.

Solo

$9/month
  • 1 user
  • Up to 10 tools monitored
  • Email alerts (immediate for critical, daily for others)
  • All 5 data sources (CISA KEV, VulnCheck, GitHub, OSV, vendor feeds)
  • Alert detail with remediation guidance
  • 7-day free trial
Start free trial
Most popular

Team

$29/month
  • 3 users
  • Up to 30 tools monitored
  • Everything in Solo
  • Slack webhook integration
  • Weekly security summary email
  • 7-day free trial
Start free trial

First to know

Our pipeline checks CISA KEV and vendor feeds every 30 minutes, often delivering verified alerts before vendors send their own customer notifications.

Verified only

Every alert is corroborated from at least 2 independent sources before we send it. Your trust is our only product.

Register your stack in 2 minutes.

7-day free trial. No credit card. Cancel without drama.

Start monitoring now