← Part 1: the consumer app Case study · Risk intelligence · B2B · 2026

Vigilo Pro.

A risk product that publishes its own failures.

The professional side of Vigilo: a live console, compliance as a product, and a public record anyone can grade.

B2B productData-dense UITrust designWeb · mobile · API
vigilo.cc/track-record
Public track record: Every call, dated. Grade it yourself.
vigilo.cc/globe · light
The globe console in the light theme
vigilo.cc/globe
31
did not confirmand still on the public
scorecard, next to the 29 that did
22days average lead on confirmed episodes
29confirmed episodes
31episodes that did not confirm
15misses tracked
48%precision, scored
3failed backtests, published

Live scorecard on vigilo.cc/track-record, read on 5 October 2026; the failed backtests are on vigilo.cc/business.

20-second summaryOwn product · B2B
What
The professional side of Vigilo: a live risk console, compliance pages and a public track record.
Why
A risk call has to be defensible for the people who sign off on the trip.
My role
Product, UX writing, data UI, design to code.
Result
22 days average lead · 29 confirmed episodes · 48% precision, scored publicly
Explore the case ↓
About

Part 1 made risk calm for a traveller. Part 2 makes it defensible for the people who sign off on the trip.

Risk intelligenceFieldB2BAudience2026Year
RoleProduct, UX writing, data UI, design to code
SurfacesLive console · compliance pages · reports · API docs · widgets · track record
ForSecurity, HR and travel managers, compliance leads, NGO programmes
Traveller · calm appSpecialist · dense console
Vigilo consumer app: home with one risk number
Vigilo consumer app: a country page
vigilo.cc/globe · watchlist
Watchlist in the console: every signal with location, category, sources and trend

Same data. Two different jobs.

A traveller asks “is it safe?”. A specialist asks “what changed, who says so, and can I show my auditor?”.

01

One number → seven domains, each traceable

02

Reassure → let them audit

03

Phone in a pocket → a second monitor all day

Why a second interface

The consumer app hides the machinery on purpose: one score, a calm voice, an action. For a security or duty-of-care lead that calm is a problem — they need to see the signals behind a number, how many sources agree, when something was first seen, and how it trends.

So Pro is not “the app with more features”. It is a different density contract: everything a specialist needs to make and defend a decision, on one screen, without the screen raising its voice.

The globe console

Dense, but never loud.

Hundreds of live signals on one screen, and only one colour is allowed to shout.

vigilo.cc/globe
1
signal colourorange means critical,
everything else is grey
Watchlist: a sortable table of every live signal
WatchlistEvery signal, sortable, with sources
Briefings: today's brief and signal cards
BriefingsAsk, or check a rumour against sources
Alerts: rules by severity, region and pathogen
AlertsRules by severity, region, pathogen
Early warning: countries, channels lit and a working theory
Early warningChannels lit, with a working theory
Density decisions
  • Grey does the work. Severity below critical is a monochrome ramp. A specialist scans for the one orange row, not a rainbow.
  • Numbers in mono. Indices, counts and “first seen” sit in a monospace face so columns align and change is visible at a glance.
  • Every row carries its proof. Source count, first-seen age and a 14-day trend live next to the headline, including when there is only one source.
  • One rail for detail. Selecting anything opens the same right rail: risk index, severity, sources, trend, brief. No modal maze.
  • Categories are switches, not tabs. Seven domains stay visible with live counts, so filtering never hides how much is happening.
Signal palette

Four greys and one alarm.

Part 1 spent colour on a five-step scale. The console spends it on one question: is this critical?

!Critical · #F26A41
AAlert · #C7D0D9
WWarning · #8E97A1
MMonitor · #5E6772
0Base · #0A0C0E
Live map in the dark theme
Night shiftDark, for the wall and the second monitor
Live map in the light theme
Day shiftLight, for reports and screenshots
On the phone

The console, one signal at a time.

On mobile the table becomes a feed: pick countries, get alerts, swipe through what changed.

Mobile onboarding: which countries to follow
Mobile feed: one critical signal over the map
Track record on mobile
B2B as a product

Designing trust, not screens.

Buyers don't buy a globe. They buy an answer for their auditor, their insurer and their board.

ISO 31030 · duty of care

Five pillars of the standard, mapped to what already runs

ISO 31030 page: the five pillars and what Vigilo covers
Compliance by role

Start from the standard your auditor asks about

Compliance by role: travel risk, continuity, climate disclosure, humanitarian
Reports

Real composites, nothing staged for the page

Live demo: three real country composites with sources
Prediction calendar

What the engine expects, day by day, 14 days out

Prediction calendar with daily batches and grading days
Geofenced alerts

Set a zone, get paged, with sources attached

Geofenced webhooks: set a zone, get paged
Embeddable widgets

One script, themed to a partner's brandbook

Widget builder: accent, radius, theme, country, with live code
API docs

One composite, seven domains, try it without a key

API docs: one risk score, every geography, seven domains
How the B2B surface is built

Sell the answer, not the dashboard. Each page starts from the buyer's question: an ISO 31030 programme, a continuity plan, a donor report. The same engine sits underneath; the page formats it for that standard.

Show real output early. The demo shows three real countries with their composites and the signals behind them, with no signup and no email gate.

Integration is a copy-paste. The widget builder writes the embed code as you tune colours and radius; the API page has a live “run request” box.

Say the scope out loud. Climate disclosure pages state that Vigilo covers physical climate inputs only and integrates with a full CSRD platform rather than pretending to be one.

Evidence layer

Don't trust the score. Check the receipt.

Every call is written to a public journal when it is made, then graded against official sources. Misses stay in the denominator.

vigilo.cc/track-record
Scorecard: confirmed episodes, average lead, episodes in flight, did not confirm, misses, precision
vigilo.cc/track-record · closed record
The full closed record: country, flagged on, lead time, signal tier
31 d

Sudan

Covert-elevated tier, called on 2026-07-13; escalation confirmed 31 days later.

3 / 3

Myanmar

Three separate watch-tier calls, each confirmed with a 30–31 day lead.

52 d

Vietnam

A safe window inside typhoon season instead of a blanket warning.

3+ mo

Russia

An election window sat in the public calendar months ahead.

Case files as published on vigilo.cc/cases. Neutral escalation signals only, no attribution.

How the record is designed

Episodes, not days. One episode is one situation in one country; days within two weeks are folded into a single call, so a six-week situation counts once, not six times.

The honest denominator. The scorecard shows the calls that did not confirm and the escalations the engine stayed silent on, next to the ones that landed.

Dated, not backfilled. Calls are written when made. The value is the gap between the flag and the headlines, verified against ReliefWeb, UN OCHA and WHO.

Lead time, not a verdict. The page says plainly that an early signal buys time to look and does not replace a team's own judgement.

Honest comparison

Say where the others are the better buy.

The comparison with Crisis24 and International SOS is about public posture, not a capability ranking, and it says when to buy them instead.

  1. 01
    They lead on people24/7 operations centres, physical and medical evacuation, in-country analysts.
  2. 02
    Vigilo competes on opennessSelf-serve sign-up, published pricing, published methodology, every score linked to its source.
  3. 03
    Gaps in writingSoftware only, no evacuation, no SOC 2 today — targeted for 2027.
vigilo.cc/compare
Side-by-side comparison of Vigilo, Crisis24, International SOS and INSO
Honesty mechanics

Rules first. Results after. Failures stay.

Trust here is a process with a paper trail, and the interface's job is to expose every step of it.

01 · Pre-registerWrite the rule downHypothesis, metric, success threshold and date, before the test runs.
02 · FreezeLock the configWeights and thresholds frozen in a dated config; the last 30 days are a holdout.
03 · JournalLog before the outcomeAppend-only, timestamped, never edited or deleted.
04 · ScoreGrade the whole recordMisses and non-confirms counted in the denominator.
05 · PublishIncluding the nullsNegative results stay on the record, with the raw report.
vigilo.cc/business · validation discipline
Three published backtests, all marked Not demonstrated
3/3
not demonstratedthree backtests that failed,
published with raw reports
48%

precision, 95% CI 36–61% · track record

58%

recall against an external ground truth · methodology

+17.4%

7-day edge over a naive baseline, out of sample · methodology

92 days

of history, listed as a known limitation · methodology

What the methodology page commits to

Accuracy is never the headline. On rare events a constant “all quiet” scores 90%+, so the page scores with Brier, false-alert rate and median lead instead.

Words are pinned to numbers. “Likely” is 55–80%, “very likely” 80–95%, “almost certain” 95%+, product-wide.

Narratives alone never escalate. Media waves count as “words”; an alert also needs a “deed” channel such as prices, reroutes or government advisories.

Known limitations are listed. Recall is 58%, history is short, and resolution is country-level; sub-national precision is roadmap, not current capability.

Sources: track record (live, read 5 Oct 2026) and methodology v1.0.

Trust centre

Procurement, without a sales call.

Privacy, security, a GDPR Art. 28 DPA, terms and prices, in one place and in plain words, honest gaps included.

Trust centre: privacy, security, methodology, DPA, terms, status
Trust centreEverything procurement needs
Data Processing Agreement draft, printable
DPADraft v0.1, print or request signed
Security page: what we don't have yet, honest roadmap
Security“What we don't have yet”
Pricing: Brief, Pro and Suite plans
PricingPublished, from a four-week pilot
Pilot · $1,500 one-offBrief · $500/moPro · $1,200/moSuite · from $30k/yrNGO · $400/mo
Final chapter · 6 October 2026

The first full windows closed. Here is the receipt, misses included.

BeforeRules frozenHypothesis, metric and threshold written down before the outcome; the last 30 days kept out of all tuning.
6 October68 episodes scored29 confirmed, 31 not confirmed, 5 unverifiable, 3 still open.
Precision48%95% interval 36–61%. Reported with the interval, never as a headline.
Lead time22 daysAverage early warning on confirmed calls, interval 19–25 days.
On the record15 missesEvents the engine did not call stay on the page. Check the live scorecard.

Figures from the public scorecard, read on 6 October 2026. It updates daily, so the live page may differ.

Main takeaway
“Trust isn't a feeling the UI creates. It's a record the UI exposes.”
For specialists, the most persuasive screen is the one that shows the misses.
What I learned
  • Density is a contract, not a style. Specialists accept a full screen when nothing on it competes for attention without a reason.
  • Copy is part of the evidence. “Not demonstrated”, “did not confirm”, “we are not a 24/7 operations centre” are product decisions written as UI text.
  • Publish the denominator. A number with its misses next to it is easier to defend in front of an auditor than a perfect-looking one.

Create bold.
Deliver better.

See our workGet in touch