ıVigíaLegal
S.00Security · Evidentiary validity

Built to withstand an audit.

The difference between having documents and having valid evidence is in how every file is sealed, custodied and transmitted. Vigía Legal uses NOM-151 with a timestamp from an authorized PSC, SAT e.firma and immutable chain of custody so every document in the file holds up before STPS, a labor court or a conciliation board.

01Evidentiary validity

Not "store PDFs". It's signed evidence.

Data message preservation

NOM-151

Every document sealed with a timestamp issued by a Certification Service Provider authorized by SE. Guarantees integrity and exact moment.

Advanced electronic signature

SAT e.firma

Signed with the vendor's legal representative e.firma. Equivalent legal validity to a handwritten signature under the Commerce Code.

Immutable audit log

Chain of custody

Every action (upload, validation, seal, signing, download) is logged with user, IP, timestamp and SHA-256 hash. Exportable as evidence.

02Infrastructure

Data in Mexico, end-to-end encryption, no model training.

Residency
Mexico (North)
AWS region mx-central-1
Encryption at rest
AES-256
keys managed via KMS
Encryption in transit
TLS 1.3
HSTS preload + certificate pinning
Backups
Point-in-time
RPO 5 min · RTO 1 h
Isolation
Logical tenancy
dedicated schema per contractor
LFPDPPP privacy
Full notice
designated DPO · ARCO online
No AI training
Contractual clause
your data does not train models
Monitoring
SIEM 24/7
anomalous alerts under 5 min
03Compliance and certifications

What we comply with and what's in progress.

We're honest: we list what's in force and what's under audit. If a certification is in progress, we say so. No marketing logos without a document behind them.

Compliant

LFPDPPP

Full privacy notice, designated DPO, ARCO registry.

Compliant

NOM-151 SE

Timestamping via PSC authorized by the Ministry of Economy.

In progress

ISO 27001

Initial audit Q3 2026. Controls already implemented.

In progress

SOC 2 Type I

Report expected Q4 2026 with external auditor.

04Roles, SoD and audit log

Approvers aren't requesters. Ever.

Vigía Legal applies segregation of duties hardcoded in the state machine. Exceptions (authorizing payment to a red vendor due to operational contingency) require at minimum three distinct roles: requester, approver, signer. Every action is recorded in an immutable audit log with SHA-256.

Granular roles

Eight profiles

admin · repse_owner · procurement · compliance · legal · contract_owner · hse · viewer. Specific permissions per resource and action.

Mandatory 2FA

TOTP + recovery

For admin · repse_owner · legal roles. Recovery codes generated on creation. Enterprise SSO with delegated MFA (Azure AD · Okta · Google Workspace).

Audit log

Immutable · SHA-256

Every action: upload, validate, reject, approve, reveal_pii, download. With actor, IP, timestamp, payload and hash chained to the previous event.

Audit log actions
uploadvalidaterejectapprovereveal_piidownloadexportexception_requestexception_approveexception_signrule_changemagic_link_sendmagic_link_usesign_repse_file
05Out of scope

What Vigía Legal does not do (and why).

As important as knowing what's included is knowing what's left out. Vigía Legal is a REPSE compliance platform — not a law firm, not a tax advisor, not a payroll system. These are the explicit boundaries:

No formal legal opinions

We don't issue legal opinions on a case-by-case basis nor represent before authorities. That's the work of a law firm. Vigía organizes the evidence your lawyer will use.

No tax determination

We don't replace your accountant or tax advisor's analysis. We cross-check information and flag inconsistencies; the final tax decision is signed by a professional.

No payroll or full EHS

We don't manage vendor payroll or a complete EHS file outside REPSE. We stay within subcontracting regulatory control.

No automated critical decisions

The system suggests ("approve" / "reject" / "hold") but the final decision is signed by a person. Regulatory compliance requires human accountability.

Let's talk

We'll send you our security whitepaper.

Threat model, incident response policy, ISO 27001 controls already implemented, data retention policy and no-training contractual clause. Request the PDF at contacto@vigialegal.mx.