Opens at launch. VibeLock is not open yet. This page describes how it will work when it opens, and will change if a decision changes before then.
VibeLock is designed to receive as little as it needs to prove a control holds.
By connection
- Your app URL
- The scan sees what anyone on the internet can see. Nothing is scanned until you ask, and only for an app you own or have permission to test.
- MCP in your coding tool
- The scan runs on your machine. VibeLock receives findings, not source code.
- Ownership proof
- A small file, tag or DNS record that VibeLock checks on your live app, or a Vercel or Netlify sign-in where VibeLock reads only which domains belong to your project.
- Repository, read-only
- Read-only access to one repository. VibeLock cannot push, commit or change settings.
Tokens
Connection tokens are per app, rate limited, and you can revoke them at any time.
When you leave
Deleting your account revokes every token, unpublishes the trust page and stops the badge link resolving. Scan history is kept for 30 days, then purged.