Download Vigia
Version 5.1.6, published 21 September 2026. One app for macOS, signed and notarized, and a signed installer for Windows. Free to download; every account comes with free server licenses.
macOS
Universal — Intel and Apple Silicon. macOS 12 or later. Signed with LockFlare Corp's Developer ID and notarized by Apple.
Download for macOSLockFlareVigia-5.1.6-mac.dmg · 36.5 MB · SHA-256 checksumf137be70f78ded044985e17a4bc3a636396f667bf849d273c8a35851cb720fc5
On first launch macOS asks whether Vigia may access files on removable volumes. That is for a key kept on a pen drive: allow it once.
Windows
64-bit Windows 10 or 11. Signed with Azure Trusted Signing, so SmartScreen knows the publisher from the first download.
Download the installerLockFlareVigia-5.1.6-win-amd64-installer.exe · 18 MB · SHA-256 checksum · Portable exe (46.2 MB)180e8c68ae97b31cc29260fde197c4415be20fd3eff79e59c52079d2fcc81cf9
Windows Hello is the second step where the computer has it; where it has not, the key's PIN — or the account's password — stands in.
The first ten minutes
Every screen of it, in order, is on getting started — the account, your key and the first server.
Create an account
One form, no card. You get an activation key: paste it into Vigia when the door asks. It is kept beside your key and carries your free server licenses.
Choose where your key lives
On a pen drive under 128 GB that leaves with you, or on this computer behind a password. Bound to this computer either way, with Touch ID or Windows Hello behind it — and Setup moves it from one to the other whenever you like.
Put a server on the map
Add a server, paste a server license, and the address comes with it. Or add a console — any box you can SSH into — for the terminal, files and tunnels with no license at all.
Turn on the backup
Setup → Encrypted backup on my key. Saved logins, certificates, buckets and snippets live only on your computer; the backup is what brings them back on the next one.
What Vigia needs from a server
An SSH login. Debian, Ubuntu, Rocky and Alma are the distributions it is proved on — apt and dnf, ufw and firewalld. Root through sudo for anything that changes the box.
What it never needs
An agent, an open port, an account with LockFlare in the path, a network connection to anything but your servers and, if you use Themis, the model provider you chose.
Verifying a download
shasum -a 256 "LockFlareVigia-5.1.6-mac.dmg" on a Mac, certutil -hashfile … SHA256 on Windows, against the checksum beside each file.