Glossary
Security terms, in plain language
The words you will meet in the checklist, the guides and your trust page, each defined in a sentence or two.
A
- Access control
- The rules that decide who can see or change what. In an app, it is the server checking, on every request, that the signed-in user is allowed to touch the record they asked for.Stop one user reading another user’s data
B
- Badge criteria
- The five conditions the VibeLock Verified badge needs, all at once: coverage of at least 80 percent, no open criticals, no highs past their deadline, a verified scan within 30 days, and an external scan plus a code connection.The VibeLock Verified badge
C
- Click-path
- A fix written as numbered steps through a hosted dashboard, for problems that live in settings rather than in code.Findings and fix prompts
- Confirmed and Likely
- How sure a scan is about a finding. Confirmed was reproduced. Likely has strong signs but was not reproduced. A Likely critical still blocks the badge until a rescan or review clears it.
- Content Security Policy
- A response header that tells the browser which sources may load scripts and other content on your pages. It limits the damage of cross-site scripting.HTTPS and security headers in ten minutes
- CORS
- Cross-origin resource sharing: the browser rule for which other websites may read responses from your API. A loose rule can let a hostile site read a signed-in user’s data.
- Coverage
- How much of your app was actually tested, out of everything the scan found to test. Forty pages found and ten reached is 25 percent. Narrowing the scan can only lower it.Coverage and the badge criteria
- Cross-site scripting (XSS)
- When content an attacker supplies runs as code in another user’s browser, usually because the app displayed it without escaping it.
F
- Fix deadline
- How long a finding may stay open, set by its severity: critical 7 days, high 30, medium 90, low none.Severities and fix deadlines
- Fix prompt
- A prompt written for your AI coding tool that describes a security fix precisely enough for the tool to make it. You paste it; your tool changes the code.
H
- HSTS
- Strict-Transport-Security, a response header that tells browsers to use HTTPS only for your domain, for a set time. A year is the usual minimum.
I
- IDOR
- Insecure direct object reference: a route that returns a record by its ID without checking it belongs to the person asking. Changing a number in the URL shows someone else’s data.Stop one user reading another user’s data
L
- Last verified
- The badge state shown when one of the five criteria does not hold today. It shows the date all five last held. Nothing is taken down.
M
- MCP
- Model Context Protocol, the standard AI coding tools use to connect to outside services. The VibeLock MCP server lets the scan run inside your coding tool, so your code stays on your machine.The VibeLock MCP server
O
- OWASP ASVS
- The OWASP Application Security Verification Standard, a published list of application security requirements. The checklist cites it for most checks.
P
- Prompt injection
- Text that talks an AI model out of its instructions, typed by a user or hidden in content the model reads. It matters most when the model can call tools or see other users’ data.
R
- Rescan
- Running a check again after a fix. In VibeLock, a finding is fixed only when a rescan confirms it.
- Row level security
- A database feature that filters every query by who is asking, so each user sees only their own rows. Essential when the browser talks to a hosted backend directly.Lock down a hosted database
S
- Secret
- Anything that grants access: an API key, a token, a password, a connection string. It belongs in environment variables on the server, never in code or the browser bundle.Rotate a leaked secret
- Severity
- How bad a finding is: Critical, High, Medium or Low. VibeLock sets it per check, and some checks move up or down under a stated condition.Severities and fix deadlines
- SQL injection
- When input a user supplies is pasted into a database query and changes what the query does. Parameterised queries prevent it.
T
- Trust page
- A public page for one app showing the controls that passed, each tied to a dated scan, plus policies and subprocessors. One link to send when someone asks whether the app is secure.The trust page
V
- Verified
- The badge state shown while all five badge criteria hold today.
- Vibe coding
- Building software mostly by describing it to an AI coding tool and accepting what it writes. Fast, and prone to the same few security gaps.