About
Who publishes this tool, where the team comes from, and what you can check yourself.
We are in this trade too
We run a managed services business ourselves. The vendor questionnaires Vigicap helps answer, we receive them too. The product came from that.
Where the team comes from
The team spent more than ten years in banking. Compliance was the daily job there, not a standard we had read.
- Ran an ISO 27001 information security management system.
- Answered vendor questionnaires from regulated clients.
- Sat through audits, on the side that has to prove things.
- Brought an entity into NIS2 and GDPR compliance.
That history is what produced Vigicap.
What you can verify without trusting us
We prefer checkable facts to arguments. Every line links to the page that proves it.
What Vigicap is not
A SOC or an EDR
Vigicap does not monitor traffic in real time and blocks nothing. It is a governance diagnostic and steering tool — it relies on the EDR and SOC you already run (or resell), it does not replace them.
A penetration test
The passive external scan reads what is already public (SPF, DKIM, DMARC, certificate, headers) to open the conversation — it is neither an intrusion nor a technical audit.
A compliance certificate
A ReCyF score or an ISO 27001 file prepared in Vigicap is neither an ANSSI accreditation nor a certification issued by an accredited body. This work shortens the audit; it does not stand in for it.
An AI tool
Vigicap calls no AI model. The action plan comes from a deterministic rule table built on the ANSSI ReCyF framework, and every proposal stays with the consultant to validate.
Who publishes Vigicap
This information is on the companies register. You can check it.
- NEXTLAB
- Simplified joint-stock company (SAS)
- Registration
- RCS Paris 108 181 421
- Registered office
- 2 avenue d'Iéna, Résidence Les Jardins de Chaillot, 75116 Paris