Remote control where the device has the final say.
Install the Vigil agent, decide on the device what it may do, then manage it from anywhere. A request the device has not allowed does not run, even when it comes from your own console.
Vigil Console
ops@acmeSend a request to the device. Try the ones it should refuse.
Device
WS-ACCOUNTING-07 · Windows 11# C:\ProgramData\Vigil\policy.toml # editable only on this device, by a local admin [screenshot] mode = "allow" [defender.scan] mode = "allow" type = ["quick"] [restart] mode = "ask" [shutdown] mode = "ask" # anything else: denyLedger on this device
Trust lives on the device.
The console asks. The device decides.
Your console, our cloud and every operator can only send requests. The agent checks each one against the policy stored on the device. A stolen console login gets exactly what the device already allows, and nothing more.
containmentNot even we can add a permission.
Policy changes happen on the device, with a local administrator's approval. No console setting, software update or support ticket can widen what a device permits.
vendor-proofSafe hands for AI agents.
Let Claude or any MCP client work on a real machine. The agent only sees the capabilities the device allows. A prompt injection can change what the model asks for. It cannot change what the device accepts.
agent-readyThree steps, one rule.
Anything a device has not explicitly allowed is denied. Everything else follows from that.
Install the agent
One signed binary for Windows. It declares typed capabilities such as
screenshot,restartanddefender.scan. It has no remote shell.Set the policy on the device
Each capability gets
allow,askordeny, with optional limits on parameters and hours. Only a local administrator can change it.Send requests from anywhere
Use the console, the API or an AI agent. Every request, verdict and result is written to a hash-chained ledger on the device.
Attackers took over a remote management platform and pushed ransomware through it to the customers of managed service providers. Between 800 and 1,500 businesses were hit in a single weekend.
Your console is the biggest target.
Most remote management tools treat the console as all-powerful, so whoever controls it controls every device. VigilantDev splits that power. A console can only request what each device already allows, and a device that never allowed software installation refuses it.
Be among the first to give your devices a veto.
We are building the first release for Windows. The agent will be open source, so you can read every line before you install it.
Tell us what you would let a remote console or an AI agent do on your machines, and what you never would.
enes@vigilantdev.com