The work

Policies

Generating the documents, why publishing one earns nothing by itself, and their standing.

VibeLock generates the security and privacy documents small companies are repeatedly asked for, filled in from your project rather than left as templates with blanks: the privacy policy, the security policy, the disclosure policy and security.txt, the incident runbook, the threat model, and an AI-use disclosure where you ship an AI feature.

On the free plan they carry a watermark. Paid plans remove it and allow publishing.

Publishing earns nothing by itself

The governance controls concern documents, and every one of them is checked, not counted. The privacy policy control satisfies the GDPR transparency articles and passes when the page is reachable. The promises control passes when every promise the policy makes resolves to a verified control. The sub-processor control passes when the list matches your stack. The runbook control passes when it names your real components.

Generating a document is therefore the first step of a fix, not the fix. Publish it where the control expects it, then re-test.

Their standing

These are generated documents and they carry that disclaimer. VibeLock is not a law firm and does not provide legal advice.

Treat them as a strong first draft that saves you the blank page and the structure, and have a lawyer review anything you will rely on, particularly anything you publish or put into a customer contract.

Note

A policy that describes controls you do not actually operate is worse than no policy. It is a written record of a claim you cannot support, and the cross-check signal will fail it.