These are written into the product, not the terms of service. They are the reason the badge is worth anything.
- Never scan without permission
- Scans run only on URLs you paste or apps you have proved are yours.
- Never write to your code
- VibeLock advises and writes prompts. Your coding tool makes the change.
- Never trust a self-report on its own
- Results from the MCP path count as self-reported until an external rescan or a second signed run backs them up.
- Never let you narrow the test to look better
- Coverage is our count, not yours. Hiding pages or skipping checks can only lower it.
- Never show you a guess
- No verified connection, no dashboard. Nothing on it is inferred.
- Never overclaim
- A trust page shows controls and dated evidence. It never says you passed SOC 2 or ISO 27001, because those cover your organisation, not your app.
Beside the audit, not instead of it
Vanta and Drata prepare an organisation for audits like SOC 2 and ISO 27001. VibeLock proves the security of one application with live scan evidence and sits beside those platforms. It is a software tool, not a security firm or an auditor, and it does not replace a qualified auditor or lawyer.