Sécurisé par conception
Imposez le SSO et l'accès par rôles, gardez la publication derrière des permissions distinctes et tenez votre code et vos prompts à l'écart de l'entraînement des modèles.
99.5%
Uptime commitment (/sla)
Encrypted
In transit and at rest
Per-project
Sandbox isolation
Off by default
Training on your data
Enterprise security controls
Les contrôles que votre équipe de sécurité attend
Identity, isolation, monitoring and scanning — wired in, not bolted on.
Access and control
SAML or OIDC single sign-on with optional SCIM provisioning on Business workspaces. Owner, Admin, Editor and Viewer roles are evaluated server-side on every request — viewing, editing, publishing and publishing publicly are separate permissions.
Guardrails for building & publishing
Editing, publishing and publishing publicly are separate permissions, and every project carries its own visibility — public, private, workspace, or named member groups. Teams move fast without exposing in-progress work.
Secrets handled securely
Encrypted at rest, scoped to your workspace, and never returned in plaintext. Rotate or revoke one and every running sandbox picks up the change immediately — no redeploy.
Where your data runs
Application servers and project sandboxes run in AWS us-east-1; the database, authentication and file storage run on Supabase in Singapore. Every subprocessor and its location is listed at /subprocessors. There is no region selector yet.
No training on your data
Vibely does not use your prompts, code, or project data to train models. Product-improvement data collection is off by default; a workspace can opt in from Privacy & security settings. Which model vendors see what is spelled out in the FAQ below.
Isolation by design
Strict logical separation between workspaces and projects with row-level security on shared databases. Boundaries are explicit before publishing.
Continuous monitoring
Rate limiting and abuse detection on the agent loop, applied at the IP, user and workspace level. Runtime errors and anomalies surface in our observability stack and we review what it flags.
Automatic security scanning
Scanners check your RLS policies, database schema, application code, dependencies and exposed PII. Findings are ranked by severity in the project Security view before you publish.
Protected infrastructure
Every build runs in its own cloud sandbox with its own filesystem, behind an edge CDN on every route. Vibely never enters your environment and needs no inbound connection from your network.
Founder security
Outils de sécurité conçus pour ceux qui livrent
From your first prototype to your Series B, you get the same controls — without the audit anxiety.
Evidence you can hand over
Export your scan findings as a report for a customer security review or investor diligence. It is a scan result, not a SOC 2 or ISO 27001 audit — but it shows exactly what was checked and what you fixed.
En savoir plusSecurity answers for founders
Ask us what we can evidence today — how builds are isolated, which subprocessors touch your data, and what we hold and do not hold on the compliance side. We hold no SOC 2 report and no ISO 27001 certificate. We answer in writing.
En savoir plusFind vulnerabilities before they find you
Five scanners check your RLS policies, database schema, application code, dependencies and exposed PII on a deep scan you run on demand; every publish additionally kicks off a background code and PII scan. Business workspaces can schedule recurring deep scans, and the safe dependency fixes can be applied for you.
En savoir plusWhere we stand on compliance
Frameworks que nous supportons
Our Data Processing Agreement is published at /dpa and applies without signature. We hold no SOC 2 report or ISO 27001 certificate today, and no audit against either is under way. The live checks at /trust are the part of this page a machine verifies.
SOC 2
Not held
We do not hold a SOC 2 report and no audit is under way. We will say so here on the day we engage an auditor, rather than before.
GDPR
EU data protection
Article 28 Data Processing Agreement published at /dpa, including the EU SCCs and the UK Addendum. It applies without signature.
ISO 27001
Not held
We do not hold an ISO 27001 certificate and no certification process is under way. What we run is described on this page; none of it is externally attested.
Prêt à construire en toute confiance ?
Livrez plus vite, avec les contrôles que votre équipe et vos clients attendent.