Understand
Build a live company profile and identify likely applicable obligations with visible reasoning.
Compliance operations · In development
Vigil brings data requests, data mapping, assessments, policies, training, regulatory change and compliance evidence into one operational workspace.
For DPO, legal and compliance teams.
Global by design. EU-first, starting with GDPR.
Workspace / Overview
Your operation, in view.
3 entities in scope
Next in your queue
Regulatory signal · Example
Updated retention guidance
May affect 2 processing activities. Review the source and impact.01 One operational layer
Requests arrive without a case owner.
Registers drift between versions.
Policies sit apart from the work.
Evidence is buried in folders.
Deadlines depend on reminders.
Updates arrive without context.
One workspace connects each obligation to its owner, deadline and evidence.
Context → action → record02 The platform
A compliance operating system for mid-sized and large international companies. The organisation’s context travels with the work.
Build a live company profile and identify likely applicable obligations with visible reasoning.
Run cases, assessments, tasks, approvals, reminders and deadlines from one workspace.
Maintain the documents, records and audit trail needed to show what happened and why.
03 Your operational view
See coverage, gaps and risk alongside the cases in progress. Know what changed, what is overdue and which decision comes next.
Monday, 14 September 2026
Company profiles reviewed
Records need an update
Assessment under review
Training follow-up
4 items shown in the example work queue.
Employee training · Example France
Data-subject request · Example Germany
DPIA · Group operations
Data mapping · Example Finland
Coverage, open risks and evidence gaps stay visible together. A reviewed profile is not a guarantee of compliance.
04 The initial pack · In development
One coherent GDPR pack connects intake, assessments, documents and evidence. Each part contributes to the same operational picture.
EU-first · In developmentA case, an owner and a deadline for every request.
Reviewed processing activities, ready for your record of processing.
Structured impact assessments with decisions and follow-up actions.
Coordinate assessment, response and the record of what happened.
Draft policies from the organisation’s actual practices.
Employee learning, quizzes and completion evidence.
Assign work, involve colleagues and bring decisions back for review.
Turn accepted information into consistent working documents.
Bring records, supporting material and activity history together.
05 Data-subject requests
A proposed workflow for the GDPR pack, from the existing privacy inbox to the final evidence record. Automation is being developed around accountable human decisions.
Through the company’s existing privacy inbox.
A proposed request type is identified for review.
The owner can check the legal deadline and its basis.
Ready for the first working day, subject to approval.
Relevant teams are asked for the information needed.
Outstanding contributions stay visible to the case owner.
Collected information becomes a draft response.
An authorised reviewer decides what can leave the organisation.
Human decisionOnly after approval, through the agreed communication channel.
The response, decisions and supporting record close the case.
People retain control over legal assessments, deadline exceptions and outbound communications. Prepared does not mean sent.
06 Data mapping
Start with what the business already knows. AI-assisted extraction proposes the structure; the DPO reviews the facts and decides what enters the register.
01 / Source material
Interview notes and existing documents supply the context.
02 / AI-assisted proposal
Candidate processing activities are linked to their sources. Missing fields become questions.
03 / DPO review
The DPO corrects the proposal. Vigil flags where a DPIA may be required, with reasoning for review.
07 Regulatory intelligence
Vigil compares regulatory developments with your company profile. Each relevant signal explains the potential impact and the work to review.
“Based on the information supplied, NIS2 is likely applicable.”
Example of a planned pack. A recommendation for review, not a definitive legal conclusion.
08 A platform that can grow
Add coherent regulatory and standards packs created by Norn Labs. The same company context, tasks and evidence can support the next area of work.
Initial pack
Operational data protection
In developmentPlanned country overlays
Buy a regulatory pack once, then add country coverage for national implementation rules, regulator guidance, local templates and relevant updates. Scope and availability will be confirmed as packs are developed.
09 By Norn Labs
Optional engine · Planned
A structured, versioned register engine designed for audit-ready records.
Optional engine · Planned
A communication engine designed to support compliant workflows.
Whistleblowing capability · Integration planned
Whistleblowing and case management within the broader Norn Labs ecosystem.
Vigil integration is planned, bringing this specialist capability into the wider compliance operation.
Explore KajaCadaster and Dispatch are optional additions. Neither is included in the default Vigil subscription.
10 Connected to your working environment
The planned connections bring inbox intake and source documents into the workflow, so teams can start with the tools they already use.
Privacy inbox intake
Documents and evidence
Privacy inbox intake
Documents and evidence
Connector scope and availability will be confirmed during development discussions.
11 Accountability by design
Norn Labs builds on European infrastructure with EU data residency. Vigil’s deployment arrangements will be confirmed with prospective customers.
Norn Labs privacy & securityThe product design keeps human approval at consequential legal and outbound steps, with recommendations linked to source information and explicit reasoning.
Access controls, auditability, encryption and evidence-retention arrangements are being defined and validated for Vigil. We will discuss the confirmed controls and deployment scope during evaluation.
Vigil supports compliance operations. It does not replace qualified legal advice.
Vigil · In development · Pre-order enquiries
Tell us about your organisation, your current processes and the work you need to bring together.
Pre-order enquiries begin a discussion. No order or payment is taken, and no launch date is promised.
Read the Vigil FAQ