Boundaries and data

What VibeLock will never do

The boundaries written into the product: permission to scan, never writing to your code, no self-reports on their own, and no overclaiming.

These are written into the product, not the terms of service. They are the reason the badge is worth anything.

Never scan without permission
Scans run only on URLs you paste or apps you have proved are yours.
Never write to your code
VibeLock advises and writes prompts. Your coding tool makes the change.
Never trust a self-report on its own
Results from the MCP path count as self-reported until an external rescan or a second signed run backs them up.
Never let you narrow the test to look better
Coverage is our count, not yours. Hiding pages or skipping checks can only lower it.
Never show you a guess
No verified connection, no dashboard. Nothing on it is inferred.
Never overclaim
A trust page shows controls and dated evidence. It never says you passed SOC 2 or ISO 27001, because those cover your organisation, not your app.

Beside the audit, not instead of it

Vanta and Drata prepare an organisation for audits like SOC 2 and ISO 27001. VibeLock proves the security of one application with live scan evidence and sits beside those platforms. It is a software tool, not a security firm or an auditor, and it does not replace a qualified auditor or lawyer.

Something unclear or out of date? Email hello@vibelock.ai or see the FAQ.