Skip to content
Confiança e segurança

Seguro por design

Aplique SSO e acesso por função, mantenha a publicação atrás de permissões separadas e deixe seu código e seus prompts fora do treinamento de modelos.

Reportar um problema

99.5%

Uptime commitment (/sla)

Encrypted

In transit and at rest

Per-project

Sandbox isolation

Off by default

Training on your data

Enterprise security controls

Os controles que sua equipe de segurança espera

Identity, isolation, monitoring and scanning — wired in, not bolted on.

Access and control

SAML or OIDC single sign-on with optional SCIM provisioning on Business workspaces. Owner, Admin, Editor and Viewer roles are evaluated server-side on every request — viewing, editing, publishing and publishing publicly are separate permissions.

Guardrails for building & publishing

Editing, publishing and publishing publicly are separate permissions, and every project carries its own visibility — public, private, workspace, or named member groups. Teams move fast without exposing in-progress work.

Secrets handled securely

Encrypted at rest, scoped to your workspace, and never returned in plaintext. Rotate or revoke one and every running sandbox picks up the change immediately — no redeploy.

Where your data runs

Application servers and project sandboxes run in AWS us-east-1; the database, authentication and file storage run on Supabase in Singapore. Every subprocessor and its location is listed at /subprocessors. There is no region selector yet.

No training on your data

Vibely does not use your prompts, code, or project data to train models. Product-improvement data collection is off by default; a workspace can opt in from Privacy & security settings. Which model vendors see what is spelled out in the FAQ below.

Isolation by design

Strict logical separation between workspaces and projects with row-level security on shared databases. Boundaries are explicit before publishing.

Continuous monitoring

Rate limiting and abuse detection on the agent loop, applied at the IP, user and workspace level. Runtime errors and anomalies surface in our observability stack and we review what it flags.

Automatic security scanning

Scanners check your RLS policies, database schema, application code, dependencies and exposed PII. Findings are ranked by severity in the project Security view before you publish.

Protected infrastructure

Every build runs in its own cloud sandbox with its own filesystem, behind an edge CDN on every route. Vibely never enters your environment and needs no inbound connection from your network.

Founder security

Ferramentas de segurança criadas para quem entrega

From your first prototype to your Series B, you get the same controls — without the audit anxiety.

Evidence you can hand over

Export your scan findings as a report for a customer security review or investor diligence. It is a scan result, not a SOC 2 or ISO 27001 audit — but it shows exactly what was checked and what you fixed.

Leia mais

Security answers for founders

Ask us what we can evidence today — how builds are isolated, which subprocessors touch your data, and what we hold and do not hold on the compliance side. We hold no SOC 2 report and no ISO 27001 certificate. We answer in writing.

Leia mais

Find vulnerabilities before they find you

Five scanners check your RLS policies, database schema, application code, dependencies and exposed PII on a deep scan you run on demand; every publish additionally kicks off a background code and PII scan. Business workspaces can schedule recurring deep scans, and the safe dependency fixes can be applied for you.

Leia mais

Where we stand on compliance

Frameworks que suportamos

Our Data Processing Agreement is published at /dpa and applies without signature. We hold no SOC 2 report or ISO 27001 certificate today, and no audit against either is under way. The live checks at /trust are the part of this page a machine verifies.

Not held

SOC 2

Not held

We do not hold a SOC 2 report and no audit is under way. We will say so here on the day we engage an auditor, rather than before.

Ativo

GDPR

EU data protection

Article 28 Data Processing Agreement published at /dpa, including the EU SCCs and the UK Addendum. It applies without signature.

Not held

ISO 27001

Not held

We do not hold an ISO 27001 certificate and no certification process is under way. What we run is described on this page; none of it is externally attested.

FAQ

Perguntas frequentes

Can't find what you need? Email [email protected] — we read every message.

Criado para a forma como você entrega

Pronto para construir com confiança?

Entregue mais rápido, com os controles que sua equipe e seus clientes esperam.

Fale com vendas