Verified security controls for vibe coded apps

Security proof
nobody typed in.

Your live app and your code, tested against the published requirements of OWASP ASVS, the GDPR and the EU AI Act. The result is a page you can send an investor.

One email when it opens. Nothing else.

VibeLock Trust CenterBound to commit 4f2a9c1
53 of 56Level 1 requirements met

Two failing controls leave three Level 1 requirements unmet

Fix them, re-test, and this reads 56 of 56. No verdict is issued either way.

  1. 01Profile sets the scope
    66 of 77 controls
    • User accounts
    • Managed auth
    • Hosted backend
    • Payments
    • Sensitive data
    • EU users
    • File uploads
    • AI feature
  2. 02Four signals test
    64 of 66 verified
    • Live URL18/18
    • Repository3/3
    • Coding tool31/33
    • Cross-check4/4
    • Provider-owned8 controls your managed auth does for you8/8
  3. 03Published requirements met
    117 of 121
    • ASVS Level 1, the minimum set53/56
    • ASVS Level 250/51
    • GDPR articles14/14
  4. =Level 1 requirements still open

    The minimum set, as OWASP defines it. A fact for the reader, not a verdict from us

    3 open
Observed, not self-attested

Built for apps made with these tools

Built for what these tools generate
  • Cursor
  • Claude Code
  • Bolt
  • Lovable
  • v0
  • Replit
  • Windsurf
  • GitHub Copilot
  • Firebase Studio
  • Cursor
  • Claude Code
  • Bolt
  • Lovable
  • v0
  • Replit
  • Windsurf
  • GitHub Copilot
  • Firebase Studio

How it works

Requirements someone else wrote, met by tests you can see

VibeLock authors none of the requirements and assigns no severity.

Profile

Eight facts decide which controls apply to your app.

Test

Four signals check them against your live app and your code.

Ledger

You get the requirements you meet, and the ones you do not.

Four tiers, none of them ours
  • Level 1OWASP ASVS 5.0
  • Level 2OWASP ASVS 5.0
  • LegalGDPR, EU AI Act
  • AdvisoryOWASP LLM Top 10

A control inherits its tier from the requirement it satisfies.

How far each signal reachesLevel 1 of 56
  • Nothing connected11
  • Live URL21
  • + repository host22
  • + your coding tool56
How coverage is derived, in full

What gets checked

Seventy-seven controls, four ways of testing them

Controls verified by each signal
  • Live URL20
  • Repository host3
  • Your coding tool49
  • Cross-checks5
The catalogue by tier77 controls
  • Level 1ASVS, the minimum set41
  • Level 2ASVS, recommended25
  • LegalGDPR, EU AI Act6
  • AdvisoryOWASP LLM Top 105

Every tier is inherited from the requirement a control satisfies.


The proof

A page you can send instead of an answer

Send a link instead of an answer. It lists what was verified, by which method, against whose requirement.

vibelock.ai/trust

Security at VibeLock

VibeLock LLC · Newest verification within 24 hours

67 verified

by VibeLock's own tests
Requirements our controls satisfyControls verified
  • OWASP ASVS 5.0

    Application security verification

    61%
  • GDPR

    Application-level articles

    6%
  • EU AI Act

    Application-level articles

    0%
Verified controls67 verified
  • Authentication and access control20 verified
  • Secrets, data and transit17 verified
  • Input, logic, API and configuration24 verified
  • Governance6 verified
Documents
  • Application and product security policy
  • Privacy policy
  • Data processing addendum
  • Subprocessors
  • Vulnerability disclosure policy
  • Acceptable use
Request documentation
Verified by VibeLock from evidence observed at a stated commit, against OWASP ASVS 5.0 and the application-level articles of the GDPR and the EU AI Act · methodology 1.0.0 · not a third party certification or audit

View VibeLock’s own Trust Center

Generated, not written

Built from what was verified, not from what you say about yourself.

No map for an attacker

No failing control, no denominator, no finding, no commit hash.

The Vibe Coding Security Checklist: 77 controls across 13 categories, four ways to check every control, four tiers and no score
Free, no account

Run the same catalogue by hand

The platform automates the checking. The document is the checking, written out, so you can do it yourself today and compare what you find with what VibeLock reports later.

  • 77 controls, 13 categories, 27 pages
  • Four ways to check every one, by hand
  • No score, no verdict, no account
Get the checklist

Pricing

What it will cost when it opens

Nothing is charged while the platform is being built. The free plan stays free.

Free

$0/mo

No card needed

See what is true today.


  • One project
  • Live URL and repository signals
  • Re-tested when you ask
Most chosen

Starter

$29/mo

$23/mo yearly−20%

Verify the whole catalog and keep it current.


Everything in Free, plus

  • Coding-tool signal and fixes
  • Continuous re-verification
  • Full Trust Center

Pro

$99/mo

$79/mo yearly−20%

More apps, a team, and alerts.


Everything in Starter, plus

  • 3 projects with team seats
  • Alerts when a control lapses
  • Trust Center on your domain

Agency

$299/mo

$239/mo yearly−20%

For studios shipping client apps.


Everything in Pro, plus

  • Unlimited projects and seats
  • White-label Trust Centers
  • API access and webhooks

Not charging your own users yet? Say so when you join and Starter is $9/mo for your first 6 months from the day you get access.


FAQ

Frequently asked questions

Do I need to be technical?

No. Every control says what it means and how it is tested, and every failed one comes with a fix you hand to your coding tool.

Is this a code scanner?

Partly. Twenty controls are probed from your live URL, three read your repository host’s alerts, forty-nine are verified by your own coding tool on your own machine, and five compare what you publish with what is verified. VibeLock never receives your source code.

Is there a score?

No, and no verdict either. You get plain fractions, such as 53 of 56 ASVS Level 1 requirements met, with the ones you do not meet named. Every requirement is published by OWASP or the European legislator, not by us.

What does my Trust Center show?

Only what is proven: verified controls, the method that proved each, and counts per framework. Never failures, denominators, findings or commit hashes. Those stay on your dashboard or a share link.

Does the evidence go stale?

Yes, deliberately. Probe evidence expires after 24 hours, and code evidence lapses when the code changes. Paid plans re-test continuously; the free plan re-tests when you ask.

Does VibeLock make me compliant?

No. It verifies application-level controls and organises the evidence. It does not certify you, does not assess your organisation, and does not replace an auditor or a lawyer. Generated policies are documents, not legal advice.

What do I get free, and can I cancel?

One project, the live URL probe and repository signals, re-tested when you ask. Paid plans add the coding-tool signal and continuous re-testing. Cancel any time from settings, or email hello@vibelock.ai.

For anything not covered here, contact hello@vibelock.ai.

Get access when VibeLock opens

One notification at launch. In the meantime, the published checklist carries the same 77 controls and the same requirements, and can be run today.