Skip to main content
Back to home

73 connectors, and what each one actually reads

Vigicap reads the real state of the tools already deployed at your client and pre-fills the relevant ANSSI ReCyF objectives. Every read produces a proposal — never a validated answer: the consultant decides.

Some products are read by a connector under a different name: Intune, Defender and Entra ID go through the Microsoft 365 connector — one OAuth application, one consent.

One key, all your clients

These tools issue a single credential to the agency, which reads all of your clients. You enter it once — not once per client.

  • Action1

    One key for all your clients

    Cloud-based patch management and vulnerability remediation. A single set of API credentials reads all of your organisations.

    • #1 Recensement des systèmes d'information
    • #5 Maîtrise des systèmes d'information
  • Huntress

    One key for all your clients

    Managed detection and response (MDR), and Microsoft 365 / Google Workspace identity posture. A single account key reads all of your organisations.

    • #1 Recensement des systèmes d'information
    • #10 Gestion des identités et des accès des u…
    • #12 Identification et réaction
    • #18 Sécurisation de la configuration des res…
  • Hudu

    One key for all your clients

    MSP operational documentation. A single key reads the tracked deadlines of all your clients: TLS certificates, domain names, warranties and custom dates.

    • #1 Recensement des systèmes d'information
  • Domotz

    One key for all your clients

    Network monitoring and device discovery. A single key reads all of your collectors: what is actually present on each site's network, not what was declared.

    • #1 Recensement des systèmes d'information
  • Liongard

    One key for all your clients

    Beta

    Automated documentation and configuration auditing. A single key reads all of your clients' environments and whatever Liongard inspects there.

  • Cisco Meraki

    One key for all your clients

    Cloud-managed network (MX firewalls, MS switches, MR access points). A single key reads all of the organisations your account has access to.

    • #1 Recensement des systèmes d'information
    • #5 Maîtrise des systèmes d'information
  • UniFi Site Manager

    One key for all your clients

    Beta

    Cloud management of UniFi (Ubiquiti) networks. A single account key reads all of the sites you administer, along with the status and firmware level of each device.

    • #1 Recensement des systèmes d'information
    • #5 Maîtrise des systèmes d'information
  • Sendmarc

    One key for all your clients

    Beta

    Hosted management of e-mail authentication (DMARC, SPF, DKIM, BIMI, MTA-STS). A single partner key reads all of your client accounts.

    • #9 Protection des systèmes d'information co…
  • Datto Autotask PSA

    One key for all your clients

    Beta

    Your PSA already knows the list of your clients: this connector imports it, then reports for each one the configuration-item inventory, their RMM coverage and warranty status. It proposes no ReCyF level. Autotask does not expose a security measurement that can be reliably interpreted.

  • HaloPSA

    One key for all your clients

    Your PSA already knows the list of your clients: this connector imports it, then reports for each one the asset inventory, their identification and their technical owner. It proposes no ReCyF level. HaloPSA records no security measurement on assets.

  • Hornetsecurity

    One key for all your clients

    Beta

    E-mail security. A single key reads all of your clients: protected domains, anti-spam and anti-malware filtering, ATP and DKIM signing, plus the state of strong authentication on the Control Panel.

    • #9 Protection des systèmes d'information co…
  • Lansweeper

    One key for all your clients

    Beta

    IT asset discovery. A single key reads all of your Lansweeper sites: per-client inventory, asset types and domains. It proposes no ReCyF level — see the note below.

  • Comet Backup

    One key for all your clients

    Beta

    Backup. A single administrator account on your Comet server reads all of your organisations: backed-up accounts, failures, and above all the accounts that have stopped backing up altogether.

    • #13 Continuité et reprise d'activité
  • Syncro

    One key for all your clients

    Beta

    PSA and RMM combined. A single key reads all of your clients: client list, monitored fleet, and the workstations the Syncro agent reports as lacking antivirus.

    • #9 Protection des systèmes d'information co…
  • Kaseya BMS

    One key for all your clients

    Beta

    PSA. A single account reads all of your clients: the list of CRM accounts and each one's hardware inventory. It proposes no ReCyF level. BMS carries no agent and records no security measurement.

  • SuperOps

    One key for all your clients

    PSA and RMM combined. A single key reads all of your clients: managed fleet, assets that no longer communicate with the RMM, and the patch status as reported by SuperOps.

    • #1 Recensement des systèmes d'information

Your tickets, in your PSA

The opposite direction to every other connector: Vigicap reads nothing here, it writes. An action from your plan becomes a ticket in the tool your team already works in, with its context and its due date.

  • ConnectWise Manage

    Beta

    Your actions go into ConnectWise Manage as tickets, with their title and description: the action plan stops being a list to re-key into the tool your technicians already work in. No ReCyF level is proposed. Pushing a ticket does not measure a client's posture.

  • Atera

    Beta

    Your actions go into Atera as tickets, with their title and description: the action plan stops being a list to re-key into the tool your technicians already work in. No ReCyF level is proposed. Pushing a ticket does not measure a client's posture.

Cloud & identity

The directory and the workstation fleet: MFA coverage, account hygiene, compliance and disk encryption.

  • Microsoft 365 / Entra ID

    OAuth connection — no credential to store

    Reads multi-factor authentication coverage, account hygiene, and — via Intune/Defender — the fleet of enrolled devices, their compliance, disk encryption and antivirus status.

    • #1 Recensement des systèmes d'information
    • #9 Protection des systèmes d'information co…
    • #10 Gestion des identités et des accès des u…
    • #18 Sécurisation de la configuration des res…
  • Google Workspace

    OAuth connection — no credential to store

    Reads two-factor authentication coverage and the domain's account hygiene.

    • #10 Gestion des identités et des accès des u…
  • Keycloak

    Self-hosted identity and SSO server (OIDC/SAML), used by MSPs as a centralised identity provider for their clients. Vigicap reads the number of users provisioned on the realm as well as the required-actions configuration (two-factor authentication enforced by default) to evaluate the ReCyF objectives « Gestion des identités et des accès » and « Authentification multi-facteurs ».

    • #10 Gestion des identités et des accès des u…
  • Authentik

    Self-hosted identity provider and SSO (OIDC/SAML), used by MSPs as a centralised IdP for their clients. Vigicap reads the number of provisioned users and the number of registered MFA devices (TOTP, WebAuthn, backup codes...) to evaluate the ReCyF objectives « Gestion des identités et des accès » and « Authentification multi-facteurs » — a signal, not proof that MFA is strictly enforced on every login.

    • #10 Gestion des identités et des accès des u…
  • Zitadel

    Self-hosted identity provider and SSO (OIDC/SAML), used by MSPs as a centralised IdP for their clients. Vigicap reads the number of provisioned users and the organisation's login policy (MFA enforced or not) to evaluate the ReCyF objectives « Gestion des identités et des accès » and « Authentification multi-facteurs » — a signal, not proof that MFA is strictly enforced on every login.

    • #10 Gestion des identités et des accès des u…
  • FreeIPA

    Beta

    Self-hosted identity directory for Linux fleets (LDAP + Kerberos), used by MSPs as the central account repository on a client's Linux servers/workstations. Vigicap reads the number of user accounts and the number of enrolled OTP tokens to evaluate the ReCyF objectives « Gestion des identités et des accès » and « Authentification multi-facteurs » — a coverage estimate, not an exhaustive per-user audit.

    • #10 Gestion des identités et des accès des u…
  • privacyIDEA

    Self-hosted, open-source multi-factor authentication (MFA) server, used by MSPs as a centralised OTP token backend (VPN, SSO, business applications). Vigicap reads the number of tokens enrolled and active on the server to evaluate the ReCyF objective « Authentification renforcée (MFA) ». The presence of active tokens proves that MFA capability is deployed, but not that it is enforced on all of the client's accounts.

    • #10 Gestion des identités et des accès des u…
  • Teleport

    Self-hosted open-source access proxy (SSH, Kubernetes, database and internal web-app bastion) with session recording. Vigicap reads the cluster's authentication policy, the number of reachable resources, the number of accounts holding an administrator or auditor role, and whether the audit log holds recent events, to evaluate the ReCyF objectives « Sécurisation des accès distants » and « Maîtrise de l'administration des systèmes d'information ». Remote access that does not go through the bastion is not visible from this source.

    • #8 Sécurisation des accès distants aux syst…
    • #11 Maîtrise de l'administration
  • HashiCorp Vault

    Self-hosted, centralised secrets manager (HashiCorp Vault OSS/Enterprise), used by MSPs to store and distribute a client's credentials, API keys and certificates rather than scattering them across scripts or configuration files. Vigicap reads the seal status (sealed/unsealed) and the list of mounted secrets engines to evaluate the ReCyF objective « Gestion des identités et des accès ». An unsealed Vault with configured secrets engines is a signal of centralised management, but guarantees neither least privilege nor the actual rotation of secrets.

    • #10 Gestion des identités et des accès des u…
  • Bitwarden

    Beta

    Enterprise password manager (self-hosted or Vaultwarden-compatible), widely used by MSPs. Vigicap reads the list of organisation members and their two-factor activation rate to evaluate the ReCyF objective « Gestion des identités et des accès ».

    • #10 Gestion des identités et des accès des u…
  • Keeper Security

    Beta

    Enterprise password vault (Keeper Enterprise) deployed by MSPs at their clients. Vigicap queries the Risk Management API (CSPM) read-only to measure the vault's actual deployment (provisioned users, populated vaults, recent logins) and the state of Keeper's security benchmarks relating to two-factor authentication. Shared-folder hygiene is not exposed by this API and is therefore not evaluated.

    • #10 Gestion des identités et des accès des u…

RMM & inventory

The real fleet: monitored machines, pending patches, antivirus status, disk encryption.

  • NinjaOne

    Beta

    RMM platform used by MSPs to monitor a client's fleet. Vigicap performs a read-only read (scope « monitoring ») of the device inventory, the system patch status, the antivirus status and the BitLocker volume encryption status, for the ReCyF objectives « Inventaire des actifs », « Gestion des correctifs », « Protection contre les codes malveillants » and « Chiffrement ». Assets with no agent and third-party application patches are not covered.

    • #1 Recensement des systèmes d'information
    • #5 Maîtrise des systèmes d'information
    • #9 Protection des systèmes d'information co…
    • #18 Sécurisation de la configuration des res…
  • Datto RMM

    Beta

    RMM platform (formerly CentraStage) used by MSPs to monitor a client's fleet. Vigicap reads — read-only — the device inventory, their online/offline status, antivirus status and patch status, for the ReCyF objectives « Inventaire des actifs », « Gestion des correctifs » and « Protection contre les codes malveillants ». Assets with no agent and third-party application patches are not covered.

    • #1 Recensement des systèmes d'information
    • #5 Maîtrise des systèmes d'information
    • #9 Protection des systèmes d'information co…
  • Kaseya VSA

    Beta

    Kaseya VSA RMM platform (VSA 9 / R9x) used by MSPs to monitor a client's fleet. Vigicap performs a read-only read of the agent inventory and samples missing system patches, for the ReCyF objectives « Inventaire des actifs » and « Gestion des correctifs ». Assets with no agent and third-party application patches are not covered.

    • #1 Recensement des systèmes d'information
    • #5 Maîtrise des systèmes d'information
  • Tactical RMM

    Beta

    Self-hosted open-source RMM. Vigicap reads the list of deployed agents (status, Windows patches pending approval) to evaluate the ReCyF objectives « Recensement des systèmes d'information » and « Maîtrise des systèmes d'information ». Only Windows patches are covered: Linux/macOS agents are not counted in the patch ratio.

    • #1 Recensement des systèmes d'information
    • #5 Maîtrise des systèmes d'information
  • MeshCentral

    Self-hosted open-source remote administration platform (endpoint agents + web console). Vigicap reads the number of enrolled devices and the number of accounts holding administrator rights to evaluate the ReCyF objectives « Recensement des systèmes d'information » and « Maîtrise de l'administration des systèmes d'information ».

    • #1 Recensement des systèmes d'information
    • #11 Maîtrise de l'administration
  • Fleet (osquery)

    Self-hosted, osquery-based fleet manager (Fleet), used by MSPs to continuously monitor a client's workstation and server fleet. Vigicap reads the list of enrolled hosts (disk encryption status) and the fleet summary to evaluate the ReCyF objectives « Inventaire des actifs », « Durcissement des postes et serveurs », « Gestion des correctifs » and « Chiffrement des données sensibles ». The presence of Fleet is a positive signal, but the detail of hardening and patching is not automatically quantified by this synchronisation.

    • #1 Recensement des systèmes d'information
    • #5 Maîtrise des systèmes d'information
    • #18 Sécurisation de la configuration des res…
  • GLPI

    Open-source IT asset and service-desk management tool (ITSM), widely used by MSPs. Vigicap reads the number of recorded assets (computers, network equipment) to evaluate the ReCyF objective « Inventaire des actifs ».

    • #1 Recensement des systèmes d'information
  • OCS Inventory

    OCS Inventory NG is a French, open-source IT-fleet inventory tool, often deployed alongside GLPI (same project family). Vigicap reads the number of machines recorded via the instance's REST API to evaluate the ReCyF objective « Inventaire des actifs ». A populated inventory is a signal, but Vigicap cannot automatically verify that it covers the entire fleet or that it is kept up to date.

    • #1 Recensement des systèmes d'information
  • Snipe-IT

    Open-source IT asset management tool, used by MSPs to record their clients' hardware. Vigicap reads the total number of registered hardware assets to evaluate the ReCyF objective « Inventaire des actifs ».

    • #1 Recensement des systèmes d'information
  • NetBox

    Open-source network infrastructure management tool (DCIM/IPAM) — inventory of racks, equipment and IP address ranges, widely used by MSPs and network teams. Vigicap reads the number of devices recorded in the DCIM module (and, for information, the number of IP addresses in the IPAM) to evaluate the ReCyF objective « Inventaire des actifs ».

    • #1 Recensement des systèmes d'information
  • IT Glue

    Beta

    Documentation platform used by MSPs to keep, client by client, the asset inventory (configurations), passwords and operational documentation up to date. Vigicap queries the API read-only and retrieves only COUNTS (no secret is ever read) to evaluate the ReCyF objectives « Inventaire des actifs » and « Maîtrise de l'écosystème ». The completeness and freshness of the documentation are not verified.

    • #1 Recensement des systèmes d'information
    • #3 Maîtrise de l'écosystème

Virtualisation

The hypervisor is the only place a virtual machine can be counted: a powered-off machine appears nowhere else. VM inventory and, on Proxmox, backup coverage.

  • Proxmox VE

    Beta

    Connects a Proxmox VE cluster to automatically inventory the client's virtual machines and check which are covered by no backup job. Feeds the ReCyF objectives for inventory and backups.

    • #1 Recensement des systèmes d'information
    • #13 Continuité et reprise d'activité
  • VMware vSphere

    Beta

    Connects VMware vCenter to automatically inventory the client's virtual machines, powered on and off alike. Feeds the ReCyF inventory objective.

    • #1 Recensement des systèmes d'information

Backup & continuity

Backups that actually run — and what no API can prove: that they have been restored.

  • Veeam

    Beta

    Connects to Veeam Backup & Replication (Community Edition or above) to automatically check that backup jobs are configured and that they run successfully, for the ReCyF objective « Sauvegardes et restauration ».

    • #13 Continuité et reprise d'activité
  • Datto BCDR

    Beta

    Connects to the Datto BCDR API (SIRIS, ALTO, NAS) to automatically check how many of the client's machines are actually protected by a Datto agent and whether their backups have run recently. Feeds the ReCyF objectives « sauvegardes » and « continuité d'activité ».

    • #13 Continuité et reprise d'activité
  • Acronis Cyber Protect

    Beta

    Connects to Acronis Cyber Protect Cloud to automatically check that the client's workstations and servers are covered by an Acronis protection plan and that their backups actually run successfully. Feeds the ReCyF objectives « sauvegardes » and « protection contre les codes malveillants ».

    • #9 Protection des systèmes d'information co…
    • #13 Continuité et reprise d'activité
  • Proxmox Backup Server

    Connects to Proxmox Backup Server (PBS), a free and open-source backup server, an alternative to Veeam for Linux/mixed fleets. Vigicap reads the configured datastores and the backups (snapshots) they contain to evaluate the ReCyF objective « Sauvegardes et restauration ». The presence of recent, frequent backups is a signal, but restore tests are not automatically verified.

    • #13 Continuité et reprise d'activité
  • UrBackup

    Beta

    Connects to UrBackup, a free and open-source backup server for Windows/Linux/macOS fleets. Vigicap reads the list of registered clients and the date of their last backup to evaluate the ReCyF objective « Sauvegardes et restauration ». Backup coverage and freshness are a signal, but restore tests are not automatically verified.

    • #13 Continuité et reprise d'activité
  • Kopia

    Self-hosted open-source backup tool, run in server mode. Vigicap reads the sources it watches and, for each one, the date of the last completed backup and the number of file errors it hit, to evaluate the ReCyF objective « Sauvegardes et restauration ». A configured source is not an executed backup: the two are counted separately. Restore tests cannot be verified — Kopia's API keeps no history of them — so this connector never proposes the top level.

    • #13 Continuité et reprise d'activité
  • Duplicati

    Self-hosted open-source backup client (workstations and small servers). Vigicap reads the configured backup jobs and, for each one, the date of the last completed backup and that of the last restore, to evaluate the ReCyF objective « Sauvegardes et restauration ». Jobs that are configured but have never run are counted separately. Duplicati records that a restore took place: the reading says so when it did, and says the opposite when it did not.

    • #13 Continuité et reprise d'activité
  • Bareos

    Open-source backup suite for mixed estates. Vigicap reads the backup jobs defined on the director, then the catalogue of runs: how many backups terminated normally, when, and how many restores were carried through. The catalogue attests that a restore happened, not that it covered all the data nor that the result was checked.

    • #13 Continuité et reprise d'activité
  • Synology DSM

    Beta

    The operating system of Synology NAS appliances. Vigicap authenticates through Synology's own published login API and reads the list of APIs the NAS exposes, which names the backup applications installed on it (Hyper Backup, Active Backup for Business, Snapshot Replication). Synology's published API exposes neither the date of the last successful backup nor any restore test: this connector therefore never proposes more than level 2 on the ReCyF objective « Sauvegardes et restauration », and that ceiling comes from the vendor's API, not from the client's backups.

    • #13 Continuité et reprise d'activité
  • Zabbix

    Self-hosted infrastructure monitoring platform (Zabbix), used by MSPs to monitor the availability of a client's servers and network equipment. Vigicap reads the number of monitored hosts and active problems to evaluate the ReCyF objective « Continuité d'activité / disponibilité ». The presence of availability monitoring is a signal of a good continuity baseline, but does not guarantee the existence of a formal continuity plan.

    • #13 Continuité et reprise d'activité

Protection & detection

EDR, antivirus, filtering, firewall, vulnerability scans and centralized logging.

  • Bitdefender GravityZone

    Beta

    Connects to the Bitdefender GravityZone console (JSON-RPC API) to automatically check how many of the client's workstations are actually managed by GravityZone, whether the antimalware module is active, and whether any workstations are reported infected. Feeds the ReCyF objectives « protection contre les codes malveillants » and « inventaire du parc ».

    • #1 Recensement des systèmes d'information
    • #9 Protection des systèmes d'information co…
  • SentinelOne

    Beta

    Connects to the SentinelOne console (Singularity) to automatically check how many agents are deployed, how many are actually connected and active, and how many threats the console has detected. Feeds the ReCyF objectives « protection contre les codes malveillants » and « détection des incidents ».

    • #9 Protection des systèmes d'information co…
    • #12 Identification et réaction
  • ThreatDown (Malwarebytes)

    Beta

    Connects to the ThreatDown API (Nebula, formerly Malwarebytes) to automatically check how many of the client's workstations carry the ThreatDown agent, how many are in a « protected » state, and how many detections were reported over the last 30 days. Feeds the ReCyF objective « protection contre les codes malveillants ».

    • #9 Protection des systèmes d'information co…
  • Sophos Central

    Beta

    Connects Sophos Central to automatically check how many of the client's devices are fully protected and on how many tamper protection is enabled. Feeds the ReCyF objectives for malware protection and secure configuration.

    • #9 Protection des systèmes d'information co…
    • #18 Sécurisation de la configuration des res…
  • ESET PROTECT

    Beta

    Connects ESET PROTECT (Cloud) to automatically check how many of the client's managed devices report no functionality alert, and to evidence an up-to-date inventory of the machines carrying the agent. Feeds the ReCyF objectives for malware protection and inventory.

    • #1 Recensement des systèmes d'information
    • #9 Protection des systèmes d'information co…
  • Wazuh

    Wazuh is an open-source SIEM/XDR platform. Vigicap authenticates against the Wazuh server API (port 55000 by default) and reads the breakdown of agents (active, disconnected, never connected): the share of active agents, which actually send their logs, serves as evidence both for centralised logging and for incident detection.

    • #12 Identification et réaction
    • #20 Supervision de la sécurité des systèmes…
  • CrowdSec

    Behaviour-based, open-source and collaborative Intrusion Prevention System (IPS), self-hosted, developed and operated from France — a sovereign alternative to proprietary intrusion detection/prevention solutions. Vigicap queries CrowdSec's Local API (LAPI) to check that it is reachable and to read the active decisions (bans, captchas) in order to evaluate the ReCyF objective « Détection des incidents ».

    • #12 Identification et réaction
  • Nessus

    Self-hosted vulnerability scanner (Nessus Essentials/Professional), used by MSPs to periodically assess the vulnerabilities of a client's fleet. Vigicap reads the list of scans (count, status, date) to evaluate the ReCyF objective « Gestion des vulnérabilités ». The presence of recent, completed scans is a signal, but does not guarantee that the vulnerabilities detected were then remediated.

    • #5 Maîtrise des systèmes d'information
  • Greenbone

    Self-hosted open-source vulnerability scanner (Greenbone Community Edition / OpenVAS). Vigicap reads the list of scan tasks (count, status, date of the last report) to evaluate the ReCyF objective « Maîtrise des systèmes d'information ». The presence of recent, completed scans is a signal, but does not guarantee that the vulnerabilities detected were then remediated.

    • #5 Maîtrise des systèmes d'information
  • DefectDojo

    Self-hosted, open-source platform that aggregates vulnerability scan results (Nessus, OpenVAS, Trivy, etc.) into engagements and findings. Vigicap reads the number of engagements and tracked vulnerabilities (including active ones) to evaluate the ReCyF objective « Gestion des vulnérabilités ». Vulnerabilities aggregated into an engagement process is a signal, but does not guarantee that those vulnerabilities are then remediated within a given timeframe.

    • #5 Maîtrise des systèmes d'information
  • TheHive

    Self-hosted open-source security incident management platform (cases, tasks, observables). Vigicap reads the number of incident cases, how many are closed and how old the most recent one is, to evaluate the ReCyF objective « Identification et réaction aux incidents de sécurité ». Those figures show that a handling process exists and is alive; they say nothing about its quality, about incidents that were never recorded, or about NIS 2 notification deadlines.

    • #12 Identification et réaction
  • Fortinet FortiGate

    Beta

    Connects a FortiGate appliance to automatically check that its security subscriptions (antivirus, IPS, web filtering) are active and how many firewall rules actually carry an inspection profile. Feeds the ReCyF objectives for malware protection and network segmentation.

    • #7 Sécurisation de l'architecture
    • #9 Protection des systèmes d'information co…
  • OPNsense / pfSense

    Beta

    Self-hosted, open-source firewall (official OPNsense API — pfSense instances share the same family of use but are not supported by this connector). Vigicap reads the number of configured filtering rules to evaluate the ReCyF objective « Cloisonnement et sécurité réseau » — a non-trivial rule set attests that filtering exists, but the quality of the segmentation (VLANs, security zones) cannot be automatically verified.

    • #7 Sécurisation de l'architecture
  • Pi-hole

    Self-hosted network DNS blocker (Pi-hole v6), used by MSPs to filter advertising/malicious domains at the client's network level. Vigicap reads the size of the blocklist (gravity) and the volume of filtered DNS queries to evaluate the ReCyF objective « Sécurisation de la messagerie et du web (filtrage DNS) ». This connector only covers DNS filtering of web traffic, not e-mail security, which caps the automatic proposal at level 3.

    • #9 Protection des systèmes d'information co…
  • AdGuard Home

    Self-hosted DNS filtering server (AdGuard Home), used by MSPs to block advertising, tracker and malicious domains at the network level. Vigicap reads the filtering status and the volume of blocked DNS queries to evaluate the « web » part of the ReCyF objective « Sécurisation de la messagerie et du web ». Mail security (anti-spam, DMARC/SPF/DKIM) is not covered by this connector, which caps the automatic proposal at level 3.

    • #9 Protection des systèmes d'information co…
  • Graylog

    Open-core platform for centralised log management (a free alternative to Wazuh for logging), self-hosted by the MSP for a client. Vigicap reads the number of configured log sources (inputs) and the volume of messages centralised over the last 24 hours to evaluate the ReCyF objective « Journalisation centralisée ». Configured inputs with no recent message indicate logging that is installed but not functioning. Objective 20 is reserved for essential entities: for a client classified as an important entity this reading is recorded in the history but changes no level, the referential not applying that objective to them.

    • #20 Supervision de la sécurité des systèmes…
  • OpenSearch

    Self-hosted search/analytics engine (open-source fork of Elasticsearch), used as the storage backend of a centralised logging stack (Fluentd/Logstash/Beats into OpenSearch). Vigicap reads the number of log indices (excluding system indices) and the cluster health status to evaluate the ReCyF objective « Journalisation centralisée ». Indices present on a degraded (red) cluster are a weaker signal than a fully healthy (green) cluster. Objective 20 is reserved for essential entities: for a client classified as an important entity this reading is recorded in the history but changes no level, the referential not applying that objective to them.

    • #20 Supervision de la sécurité des systèmes…
  • Grafana Loki

    Open-source log-aggregation system (Grafana Loki), self-hosted by the MSP to centralise a client's logs (often fed by Promtail/Grafana Alloy). Vigicap checks that the instance is operational and reads the number of indexed log labels to evaluate the ReCyF objective « Journalisation centralisée ». A reachable instance with no labels at all indicates that no log stream is currently centralised. Objective 20 is reserved for essential entities: for a client classified as an important entity this reading is recorded in the history but changes no level, the referential not applying that objective to them.

    • #20 Supervision de la sécurité des systèmes…

Email & awareness

Mail filtering and user training — the two objectives no technical tool covers.

  • Vade

    Beta

    Mail filtering gateway published by Vade, a French company based in Hem (Hauts-de-France): clients' e-mail flows remain processed by a sovereign solution, a decisive argument for entities subject to the « cloud de confiance » doctrine. Vigicap reads the inbound filtering log, read-only, to evaluate the ReCyF objective « Sécurité de la messagerie » — volume of messages analysed, threats detected and the share actually blocked. Outbound filtering and SPF/DKIM/DMARC posture are not evaluated.

    • #9 Protection des systèmes d'information co…
  • GoPhish

    Self-hosted, open-source phishing-simulation platform, used by MSPs to run controlled campaigns against a client's staff and measure their reactions (opens, clicks, credential entry). Vigicap reads the list of campaigns and their results to evaluate the ReCyF objective « Sensibilisation ». The presence of campaigns and a low click-through rate are positive signals, but do not guarantee the quality of the training content or its follow-up.

    • #4 Intégration de la sécurité numérique dan…
  • KnowBe4

    Beta

    SaaS security-awareness training platform widely deployed by MSPs: training campaigns assigned to staff and phishing simulations. Vigicap reads the Reporting API read-only to evaluate the ReCyF objective « Sensibilisation » — number of campaigns, training completion rate and simulation click-through rate. The training content, the frequency of campaigns and the actual coverage of the workforce are not verified.

    • #4 Intégration de la sécurité numérique dan…

The trademarks and logos mentioned belong to their respective owners and identify the tools Vigicap is compatible with — see the legal notice.