Skip to content

Security

Find the holes first

Vibely scans your code, packages and Supabase database, ranks what it finds, and turns each finding into a fix you can send to the agent. Both scans are free.

Vibely scans every app it builds. A basic scan checks code and sensitive data on every publish, without blocking it. A deep scan adds dependencies, row-level security and database checks. Findings come with suggested fixes you can send to the agent, both scans are free on every plan, and the Security center on Business covers every project at once.

Five scanners, one list

Every finding lands in the project’s Security view, ranked Error, Warning or Info, with the file it’s in and a suggested fix.

  • Row-level security

    Finds Supabase tables with row-level security off or policies that let anyone read or change other people’s rows.
  • Database security

    Checks your database functions and grants, including SECURITY DEFINER functions that run with more access than they should.
  • Code review

    Hardcoded secrets (211 rules plus an entropy check), eval, unsafe HTML, server secrets in client code and insecure URLs, with mobile rules too.
  • Dependency audit

    Looks up every package against known vulnerabilities and can apply the non-major upgrades that fix them for you.
  • Sensitive data

    Flags personal data such as email addresses or phone numbers written into your code where visitors could see it.
  • Security score

    One grade per project, Excellent, Good, Fair or At risk, from the open findings: 25 points off per Error, 5 per Warning, 1 per Info.

When the scans run

  • Basic scan

    On every publish

    Code and sensitive data, in the background. It doesn’t hold up the publish.

  • Deep scan

    On demand

    Adds dependencies, row-level security and database checks.

  • Cost

    Both free

    On every plan, including Free. Scans never use credits.

Built for the people who sign off

  • Guardrails for publishing

    On every plan, block publishing while there are critical issues and require a scan before a project is first published. On Business, also block publishing when personal data is found, require two-factor authentication to publish, choose who can publish, and stop chat messages that look like secrets.
    Read the publishing guardrails
  • Security center

    Business plan
    One dashboard for every project in the workspace, ranked by how urgently each needs review: code findings, vulnerable packages and stored secrets (by name only). Schedule weekly or monthly deep scans and export to CSV.
    Read about the Security center
  • Audit logs

    Business plan
    A searchable record of who changed what: members and roles, publishing and settings, with filters and CSV export.
    See audit logs for teams
  • Leaked password protection

    With Supabase linked, one switch in the Security view blocks sign-ups and password changes that use passwords found in known data breaches.

Frequently asked questions

No. The basic scan and the deep scan are both free on every plan. Fixing a finding sends it to the agent as a build request, like any other change you ask for.

Not by default. The basic scan runs in the background while you publish. A workspace admin can choose to block publishing when there are critical issues, or to require a scan before a project is first published.

Only for the row-level security and database scanners, which read your connected Supabase project. Code review, the dependency audit and the sensitive-data check work on any project.

No. A scan catches common problems, not every possible risk. Review the changes, test your sign-in and data access yourself after fixes, and scan again.

This page is about scanning the apps you build. How Vibely itself protects your account and data, and our compliance documents, are on the Vibely security and trust page.