Skip to main content
Back to home

Your SOC detects. Vigicap keeps the register and the clocks.

A qualified alert becomes a dated incident, and three clocks start. Vigicap computes them, watches them and warns you before each one — it files nothing on your behalf.

  • Three deadlines, computed from the moment of awareness

    When the incident is created, Vigicap sets the three Article 23 milestones from the date you became aware of it: pre-notification at 24 hours, notification at 72 hours, final report at one month. A job checks every fifteen minutes and emails the administrators before each deadline. Correcting the awareness date recomputes all three.

  • The right national recipient, written into the draft

    The draft pre-notification names the authority for the client's country: ANSSI in France, BSI in Germany, CSIRT Italia, CSIRT NASK in Poland, the CCB in Belgium, NCSC-NL in the Netherlands. With no jurisdiction recorded it says so instead of assuming France. The text is deterministic, with no AI model, and you are the one who sends it: Vigicap files nothing with an authority.

  • From alert to incident, by an analyst's decision

    Imported alerts land in a per-client queue. An analyst dismisses one with a reason, or qualifies it into an incident — and that is the moment, never on its own, when the clocks start. Today one integration feeds that queue, TheHive; the other SIEM connectors are read for their posture, and the connectors page says which does what.

  • CERT-FR advisories, matched against each client

    Vigicap follows CERT-FR alerts, advisories and news, and matches the products named in a bulletin against each client's connectors. What you read is “this client has a connector for a product named here” — not “this client is vulnerable”. There is no scan and no CVE database: the source is CERT-FR.

  • A monthly service report, per client

    Every client gets their service month: alerts received and triaged, incidents opened and resolved, NIS 2 deadlines met, connector coverage. Anything that was not measured says so — never a zero, because a zero reads as "instant". You record your contractual commitments there (triage of an alert, resolution of an incident) and the report checks them against the SLOWEST alert of the month rather than the median: "met" means met on every one.

  • An analyst sees only their clients, if you switch it on

    The setting belongs to the agency. Once it is on, a consultant reaches only the clients assigned to them, and an attempt on another answers “not found” rather than “forbidden”, so as not to confirm it exists. Administrators and leads are never restricted, and the setting is off by default.

  • Who sees what, and how the portfolio is filed

    A read-only seat opens the whole file and can write nothing to it — for an auditor, a client, someone new. And clients group by label: "managed SOC", "under contract", whatever you use, with a portfolio filter that appears as soon as one label exists.

Your tools, read-only

SIEM and logging, case management, vulnerability scanners, EDR, identity, backup: every connector states what it reads at the client and which ReCyF objective it fills in. The rights it asks for are written on its own page.

See the connectors

The rest of the platform does not change

The ReCyF diagnostic, action plan, quote, white-label report and ISO 27001 module serve an MSSP as they serve an MSP. This page only describes what serves a security service centre first.