Skip to content
Confianza y seguridad

Seguro por diseño

Aplica SSO y acceso por roles, mantén la publicación detrás de permisos independientes y deja tu código y tus prompts fuera del entrenamiento de modelos.

Reportar un problema

99.5%

Uptime commitment (/sla)

Encrypted

In transit and at rest

Per-project

Sandbox isolation

Off by default

Training on your data

Enterprise security controls

Los controles que tu equipo de seguridad espera

Identity, isolation, monitoring and scanning — wired in, not bolted on.

Access and control

SAML or OIDC single sign-on with optional SCIM provisioning on Business workspaces. Owner, Admin, Editor and Viewer roles are evaluated server-side on every request — viewing, editing, publishing and publishing publicly are separate permissions.

Guardrails for building & publishing

Editing, publishing and publishing publicly are separate permissions, and every project carries its own visibility — public, private, workspace, or named member groups. Teams move fast without exposing in-progress work.

Secrets handled securely

Encrypted at rest, scoped to your workspace, and never returned in plaintext. Rotate or revoke one and every running sandbox picks up the change immediately — no redeploy.

Where your data runs

Application servers and project sandboxes run in AWS us-east-1; the database, authentication and file storage run on Supabase in Singapore. Every subprocessor and its location is listed at /subprocessors. There is no region selector yet.

No training on your data

Vibely does not use your prompts, code, or project data to train models. Product-improvement data collection is off by default; a workspace can opt in from Privacy & security settings. Which model vendors see what is spelled out in the FAQ below.

Isolation by design

Strict logical separation between workspaces and projects with row-level security on shared databases. Boundaries are explicit before publishing.

Continuous monitoring

Rate limiting and abuse detection on the agent loop, applied at the IP, user and workspace level. Runtime errors and anomalies surface in our observability stack and we review what it flags.

Automatic security scanning

Scanners check your RLS policies, database schema, application code, dependencies and exposed PII. Findings are ranked by severity in the project Security view before you publish.

Protected infrastructure

Every build runs in its own cloud sandbox with its own filesystem, behind an edge CDN on every route. Vibely never enters your environment and needs no inbound connection from your network.

Founder security

Herramientas de seguridad construidas para quienes lanzan

From your first prototype to your Series B, you get the same controls — without the audit anxiety.

Evidence you can hand over

Export your scan findings as a report for a customer security review or investor diligence. It is a scan result, not a SOC 2 or ISO 27001 audit — but it shows exactly what was checked and what you fixed.

Leer más

Security answers for founders

Ask us what we can evidence today — how builds are isolated, which subprocessors touch your data, and what we hold and do not hold on the compliance side. We hold no SOC 2 report and no ISO 27001 certificate. We answer in writing.

Leer más

Find vulnerabilities before they find you

Five scanners check your RLS policies, database schema, application code, dependencies and exposed PII on a deep scan you run on demand; every publish additionally kicks off a background code and PII scan. Business workspaces can schedule recurring deep scans, and the safe dependency fixes can be applied for you.

Leer más

Where we stand on compliance

Frameworks que soportamos

Our Data Processing Agreement is published at /dpa and applies without signature. We hold no SOC 2 report or ISO 27001 certificate today, and no audit against either is under way. The live checks at /trust are the part of this page a machine verifies.

Not held

SOC 2

Not held

We do not hold a SOC 2 report and no audit is under way. We will say so here on the day we engage an auditor, rather than before.

Activo

GDPR

EU data protection

Article 28 Data Processing Agreement published at /dpa, including the EU SCCs and the UK Addendum. It applies without signature.

Not held

ISO 27001

Not held

We do not hold an ISO 27001 certificate and no certification process is under way. What we run is described on this page; none of it is externally attested.

FAQ

Preguntas frecuentes

Can't find what you need? Email [email protected] — we read every message.

Construido para la forma en que lanzas

¿Listo para construir con confianza?

Lanza más rápido, con los controles que tu equipo y tus clientes esperan.

Contactar a ventas