Security proof
nobody typed in.
Your live app and your code, tested against the published requirements of OWASP ASVS, the GDPR and the EU AI Act. The result is a page you can send an investor.
Two failing controls leave three Level 1 requirements unmet
Fix them, re-test, and this reads 56 of 56. No verdict is issued either way.
- 01Profile sets the scope66 of 77 controls
- User accounts
- Managed auth
- Hosted backend
- Payments
- Sensitive data
- EU users
- File uploads
- AI feature
- 02Four signals test64 of 66 verified
- Live URL18/18
- Repository3/3
- Coding tool31/33
- Cross-check4/4
- Provider-owned8 controls your managed auth does for you8/8
- 03Published requirements met117 of 121
- ASVS Level 1, the minimum set53/56
- ASVS Level 250/51
- GDPR articles14/14
- 3 open=Level 1 requirements still open
The minimum set, as OWASP defines it. A fact for the reader, not a verdict from us
Built for apps made with these tools
- Cursor
- Claude Code
- Bolt
- Lovable
- v0
- Replit
- Windsurf
- GitHub Copilot
- Firebase Studio
- Cursor
- Claude Code
- Bolt
- Lovable
- v0
- Replit
- Windsurf
- GitHub Copilot
- Firebase Studio
Requirements someone else wrote, met by tests you can see
VibeLock authors none of the requirements and assigns no severity.
Profile
Eight facts decide which controls apply to your app.
Test
Four signals check them against your live app and your code.
Ledger
You get the requirements you meet, and the ones you do not.
- Level 1OWASP ASVS 5.0
- Level 2OWASP ASVS 5.0
- LegalGDPR, EU AI Act
- AdvisoryOWASP LLM Top 10
A control inherits its tier from the requirement it satisfies.
- Nothing connected11
- Live URL21
- + repository host22
- + your coding tool56
Seventy-seven controls, four ways of testing them
- Live URLfrom outside20
- Repository hostalerts only3
- Your coding toolon your machine49
- Cross-checksagainst documents5
- Level 1ASVS, the minimum set41
- Level 2ASVS, recommended25
- LegalGDPR, EU AI Act6
- AdvisoryOWASP LLM Top 105
Every tier is inherited from the requirement a control satisfies.
A page you can send instead of an answer
Send a link instead of an answer. It lists what was verified, by which method, against whose requirement.
Security at VibeLock
VibeLock LLC · Newest verification within 24 hours67 verified
by VibeLock's own tests- 61%
OWASP ASVS 5.0
Application security verification
- 6%
GDPR
Application-level articles
- 0%
EU AI Act
Application-level articles
- Authentication and access control20 verified
- Secrets, data and transit17 verified
- Input, logic, API and configuration24 verified
- Governance6 verified
- Application and product security policy
- Privacy policy
- Data processing addendum
- Subprocessors
- Vulnerability disclosure policy
- Acceptable use
View VibeLock’s own Trust Center
Generated, not written
Built from what was verified, not from what you say about yourself.
No map for an attacker
No failing control, no denominator, no finding, no commit hash.

Run the same catalogue by hand
The platform automates the checking. The document is the checking, written out, so you can do it yourself today and compare what you find with what VibeLock reports later.
- 77 controls, 13 categories, 27 pages
- Four ways to check every one, by hand
- No score, no verdict, no account
What it will cost when it opens
Nothing is charged while the platform is being built. The free plan stays free.
Free
$0/mo
See what is true today.
- One project
- Live URL and repository signals
- Re-tested when you ask
Starter
$29/mo
Verify the whole catalog and keep it current.
Everything in Free, plus
- Coding-tool signal and fixes
- Continuous re-verification
- Full Trust Center
Pro
$99/mo
More apps, a team, and alerts.
Everything in Starter, plus
- 3 projects with team seats
- Alerts when a control lapses
- Trust Center on your domain
Agency
$299/mo
For studios shipping client apps.
Everything in Pro, plus
- Unlimited projects and seats
- White-label Trust Centers
- API access and webhooks
Not charging your own users yet? Say so when you join and Starter is $9/mo for your first 6 months from the day you get access.
Frequently asked questions
Do I need to be technical?
No. Every control says what it means and how it is tested, and every failed one comes with a fix you hand to your coding tool.
Is this a code scanner?
Partly. Twenty controls are probed from your live URL, three read your repository host’s alerts, forty-nine are verified by your own coding tool on your own machine, and five compare what you publish with what is verified. VibeLock never receives your source code.
Is there a score?
No, and no verdict either. You get plain fractions, such as 53 of 56 ASVS Level 1 requirements met, with the ones you do not meet named. Every requirement is published by OWASP or the European legislator, not by us.
What does my Trust Center show?
Only what is proven: verified controls, the method that proved each, and counts per framework. Never failures, denominators, findings or commit hashes. Those stay on your dashboard or a share link.
Does the evidence go stale?
Yes, deliberately. Probe evidence expires after 24 hours, and code evidence lapses when the code changes. Paid plans re-test continuously; the free plan re-tests when you ask.
Does VibeLock make me compliant?
No. It verifies application-level controls and organises the evidence. It does not certify you, does not assess your organisation, and does not replace an auditor or a lawyer. Generated policies are documents, not legal advice.
What do I get free, and can I cancel?
One project, the live URL probe and repository signals, re-tested when you ask. Paid plans add the coding-tool signal and continuous re-testing. Cancel any time from settings, or email hello@vibelock.ai.
For anything not covered here, contact hello@vibelock.ai.
Get access when VibeLock opens
One notification at launch. In the meantime, the published checklist carries the same 77 controls and the same requirements, and can be run today.