Skip to content
Kepercayaan & keamanan

Aman sejak desain

Terapkan SSO dan akses berbasis peran, jaga agar penerbitan berada di balik izin terpisah, dan jauhkan kode serta prompt Anda dari pelatihan model.

Laporkan masalah

99.5%

Uptime commitment (/sla)

Encrypted

In transit and at rest

Per-project

Sandbox isolation

Off by default

Training on your data

Enterprise security controls

Kontrol yang diharapkan oleh tim keamanan Anda

Identity, isolation, monitoring and scanning — wired in, not bolted on.

Access and control

SAML or OIDC single sign-on with optional SCIM provisioning on Business workspaces. Owner, Admin, Editor and Viewer roles are evaluated server-side on every request — viewing, editing, publishing and publishing publicly are separate permissions.

Guardrails for building & publishing

Editing, publishing and publishing publicly are separate permissions, and every project carries its own visibility — public, private, workspace, or named member groups. Teams move fast without exposing in-progress work.

Secrets handled securely

Encrypted at rest, scoped to your workspace, and never returned in plaintext. Rotate or revoke one and every running sandbox picks up the change immediately — no redeploy.

Where your data runs

Application servers and project sandboxes run in AWS us-east-1; the database, authentication and file storage run on Supabase in Singapore. Every subprocessor and its location is listed at /subprocessors. There is no region selector yet.

No training on your data

Vibely does not use your prompts, code, or project data to train models. Product-improvement data collection is off by default; a workspace can opt in from Privacy & security settings. Which model vendors see what is spelled out in the FAQ below.

Isolation by design

Strict logical separation between workspaces and projects with row-level security on shared databases. Boundaries are explicit before publishing.

Continuous monitoring

Rate limiting and abuse detection on the agent loop, applied at the IP, user and workspace level. Runtime errors and anomalies surface in our observability stack and we review what it flags.

Automatic security scanning

Scanners check your RLS policies, database schema, application code, dependencies and exposed PII. Findings are ranked by severity in the project Security view before you publish.

Protected infrastructure

Every build runs in its own cloud sandbox with its own filesystem, behind an edge CDN on every route. Vibely never enters your environment and needs no inbound connection from your network.

Founder security

Alat keamanan yang dibangun untuk para pengirim

From your first prototype to your Series B, you get the same controls — without the audit anxiety.

Evidence you can hand over

Export your scan findings as a report for a customer security review or investor diligence. It is a scan result, not a SOC 2 or ISO 27001 audit — but it shows exactly what was checked and what you fixed.

Baca selengkapnya

Security answers for founders

Ask us what we can evidence today — how builds are isolated, which subprocessors touch your data, and what we hold and do not hold on the compliance side. We hold no SOC 2 report and no ISO 27001 certificate. We answer in writing.

Baca selengkapnya

Find vulnerabilities before they find you

Five scanners check your RLS policies, database schema, application code, dependencies and exposed PII on a deep scan you run on demand; every publish additionally kicks off a background code and PII scan. Business workspaces can schedule recurring deep scans, and the safe dependency fixes can be applied for you.

Baca selengkapnya

Where we stand on compliance

Framework yang kami dukung

Our Data Processing Agreement is published at /dpa and applies without signature. We hold no SOC 2 report or ISO 27001 certificate today, and no audit against either is under way. The live checks at /trust are the part of this page a machine verifies.

Not held

SOC 2

Not held

We do not hold a SOC 2 report and no audit is under way. We will say so here on the day we engage an auditor, rather than before.

Aktif

GDPR

EU data protection

Article 28 Data Processing Agreement published at /dpa, including the EU SCCs and the UK Addendum. It applies without signature.

Not held

ISO 27001

Not held

We do not hold an ISO 27001 certificate and no certification process is under way. What we run is described on this page; none of it is externally attested.

FAQ

Pertanyaan yang sering diajukan

Can't find what you need? Email [email protected] — we read every message.

Dibangun untuk cara Anda mengirim

Siap membangun dengan percaya diri?

Kirim lebih cepat, dengan kontrol yang diharapkan tim dan pelanggan Anda.

Hubungi penjualan