Opens at launch. VibeLock is not open yet. This page describes how it will work when it opens, and will change if a decision changes before then.
Anyone can paste a shield image onto a website. The VibeLock Verified badge links to a live verification page that shows its current state, and that state changes as soon as the evidence does. A screenshot proves nothing. The link does.
The five criteria
All five are required, every time.
- Coverage of at least 80 percent.
- No open critical findings.
- No high findings past their fix deadline.
- A verified scan within the last 30 days.
- Checked from outside and inside: an external scan plus at least one code connection, the VibeLock MCP server or GitHub.
The public wording of these criteria is still being finalised. The criteria themselves are decided.
What the badge shows
- Verified
- All five criteria hold today. The badge shows the date of the last verified scan and links to the criteria.
- Last verified
- A criterion does not hold today. The badge shows the date the five criteria last held. Nothing is taken down.
What moves it
The badge reads Verified only while all five criteria hold. When one stops holding (a new critical, a high past its deadline, coverage under 80%, no verified scan for 30 days, or a connection lost for more than 14 days) it shows your last verified date instead. The next verified scan brings Verified back. At 21 days you get a private reminder with a one-click rescan. Your trust page stays up throughout.
Findings from the MCP path alone cannot earn the badge. They need an external rescan or a second signed run to back them up.