Security
Find the holes first
Vibely scans your code, packages and Supabase database, ranks what it finds, and turns each finding into a fix you can send to the agent. Both scans are free.
Vibely scans every app it builds. A basic scan checks code and sensitive data on every publish, without blocking it. A deep scan adds dependencies, row-level security and database checks. Findings come with suggested fixes you can send to the agent, both scans are free on every plan, and the Security center on Business covers every project at once.
Five scanners, one list
Every finding lands in the project’s Security view, ranked Error, Warning or Info, with the file it’s in and a suggested fix.
Row-level security
Finds Supabase tables with row-level security off or policies that let anyone read or change other people’s rows.Database security
Checks your database functions and grants, including SECURITY DEFINER functions that run with more access than they should.Code review
Hardcoded secrets (211 rules plus an entropy check), eval, unsafe HTML, server secrets in client code and insecure URLs, with mobile rules too.Dependency audit
Looks up every package against known vulnerabilities and can apply the non-major upgrades that fix them for you.Sensitive data
Flags personal data such as email addresses or phone numbers written into your code where visitors could see it.Security score
One grade per project, Excellent, Good, Fair or At risk, from the open findings: 25 points off per Error, 5 per Warning, 1 per Info.
When the scans run
Basic scan
On every publish
Code and sensitive data, in the background. It doesn’t hold up the publish.
Deep scan
On demand
Adds dependencies, row-level security and database checks.
Cost
Both free
On every plan, including Free. Scans never use credits.
Built for the people who sign off
Guardrails for publishing
On every plan, block publishing while there are critical issues and require a scan before a project is first published. On Business, also block publishing when personal data is found, require two-factor authentication to publish, choose who can publish, and stop chat messages that look like secrets.Read the publishing guardrailsSecurity center
Business planOne dashboard for every project in the workspace, ranked by how urgently each needs review: code findings, vulnerable packages and stored secrets (by name only). Schedule weekly or monthly deep scans and export to CSV.Read about the Security centerAudit logs
Business planA searchable record of who changed what: members and roles, publishing and settings, with filters and CSV export.See audit logs for teamsLeaked password protection
With Supabase linked, one switch in the Security view blocks sign-ups and password changes that use passwords found in known data breaches.
Read more about app security
- Docs
The Security view
Run scans, read findings and fix or ignore them.
- Docs
Security center
Every project’s findings in one place, on Business.
- Docs
Security best practices
What to check before you share an app.
- Trust
Vibely platform security
How Vibely protects your account, data and code.
Keep exploring
How to secure a vibe-coded app
A step-by-step guide to the checks that matter most.
Keep exploring
Database and auth
Row-level security is on from the first migration.
Keep exploring
Publishing
The basic scan runs every time you publish.
Keep exploring
Client portal use case
Keep each client’s data to that client.
Found a vulnerability in Vibely itself? Report it through responsible disclosure. Our policies are collected in the legal hub, and plan details are on pricing.