FAQ

Frequently asked questions

Short answers. The documentation has the detail.

VibeLock

Can I use VibeLock today?

Not yet. Today you can use the free checklist and the Vibe Coding Security OS. Join the waitlist and we'll email you once when VibeLock opens. Nothing is charged until the trust page and badge ship.

Is there a security score?

No. A single number is a verdict you can't act on. You see the facts instead: which of the five badge criteria hold, your coverage, and every open finding with its severity and deadline. The free preview shows findings tagged Confirmed or Likely.

What does "coverage" mean?

How much of your app we tested, out of everything we found to test. Find 40 pages, reach 10, and coverage is 25%. The badge needs 80%. We do the counting, so hiding pages can only lower it.

What happens if I stop rescanning, or a new issue turns up?

Nothing is taken down. Your badge reads Verified only while all five criteria hold: coverage of at least 80%, no open criticals, no highs past deadline, a verified scan in the last 30 days, and an external scan plus a code connection. If one stops holding, the badge and trust page show the date you were last verified instead. The next verified scan brings Verified back. You get a private rescan reminder at 21 days.

What does the MCP path see?

The scan runs inside Claude Code or Cursor on your machine; your code never leaves it. VibeLock receives findings only, and counts them as self-reported until an external rescan or a second signed run backs them up.

Does VibeLock replace Vanta or Drata?

No. They prepare your organisation for audits like SOC 2 and ISO 27001. VibeLock proves your app with live scan evidence, beside them. A trust page never claims you passed an audit.

Scanning and your code

Will VibeLock scan an app I do not own?

No. Scans run only on URLs you paste, for an app you own or have permission to test, and deeper scans need proof that the app is yours.

How do I prove the app is mine?

On any host, add a small verification file or a one-line tag to your app (your AI builder can do it from a prompt we give you), or add a DNS record on your own domain. If your app is on Vercel or Netlify, you can sign in instead. Connecting GitHub, Claude Code or Cursor connects your code but does not prove the app is yours, because anyone can copy code.

Does VibeLock change my code?

No. VibeLock never writes to your code. It explains each finding and gives you a prompt for your AI coding tool, which makes the change while you stay in control.

Does my source code leave my machine?

Not through the MCP path: the scan runs inside your coding tool and VibeLock receives findings, not source. The GitHub connection is read-only access to one repository and cannot push or change settings.

Do I install the MCP server on my machine?

No. The VibeLock MCP server is hosted and reached over HTTPS. In Claude Code you install a plugin that connects to it; in Cursor you add the server in settings. You approve it on a sign-in consent screen and choose the app it scans for.

Is active attack testing switched on?

No. Scanning is safe mode only, and active testing is never switched on by default.

Findings, severities and the badge

How are severities set?

VibeLock sets a severity per check: Critical, High, Medium or Low. Some checks move up or down under a stated condition, for example a leaked secret that still works in a public repository is critical. The same severities are printed in the free checklist.

How long do I have to fix something?

Critical 7 days, high 30, medium 90, low has no deadline. A critical left open, or a high past its deadline, means the badge shows your last verified date instead of Verified.

Can I dismiss a finding?

No. A finding is closed by a rescan that confirms the fix, or for a Likely finding by a confirming rescan or VibeLock review. The person being checked can never dismiss it.

Can the trust page be taken down?

Not for age, a lost connection, billing or a downgrade. It shows Verified or the date you were last verified. Only deleting your account, losing ownership of the app, or abuse removes it.

Plans and the waitlist

What does it cost?

Free is $0. Founder is $99 a month, or $79 billed annually. Team is $299 a month, or $249 billed annually. Enterprise starts at $999 a month and is sales-assisted. Nothing is charged until the trust page and badge ship.

What happens when I join the waitlist?

We store your email and, if you gave one, your app URL. Nothing is scanned. We email you once when VibeLock opens, and your passive preview runs when you click that email.

What can I use today?

The free pre-launch security checklist, and the Vibe Coding Security OS in Notion.

Not answered here? Email hello@vibelock.ai.