Security

What we commit to, and what we have not done yet

VibeLock holds the security posture of other people’s projects. If it were breached it would expose exactly the material its customers were trying to organise, so every practice the product asks for has to hold here first.

True today

Controls that are implemented and verifiable today, rather than intentions written in the present tense.

Data minimisation
API key values, submitted code, plaintext passwords, health data and card numbers are never stored. Data that is never collected cannot be exposed.
Multi factor authentication on production systems
Required on every third party account that can reach customer data or deploy code.
Disclosure programme
Open from before launch. Acknowledgement within 24 hours, a resolution timeline within 72, and no legal action against researchers acting in good faith.
Published legal documents
Terms, privacy policy, data processing addendum, subprocessor list and acceptable use, all public rather than available on request.
Breach notification commitment
Affected users notified within 72 hours of confirming a breach, running from awareness rather than from the end of an investigation.
Our own posture published
The trust page shows what is in place and what is outstanding, including the items we have not done.

Still ahead

Listed without target dates. A date attached to a commitment that cannot yet be met is a claim, not a plan.

Independent penetration test
Before general availability. No firm has been engaged yet, and we will name them here once one has been.
Our own Trust Center, published
Computed by the same method customers get, from real evidence, with no exception for us. It publishes when the platform does.
First full incident drill
The playbook is documented. Executing it end to end is a separate exercise, and has not yet been carried out.
Documented retention schedule
Retention is currently described in the privacy policy but not yet held as a separate operational schedule.
Formal access review
Least privilege is applied when access is granted. A recurring review of who still holds what is not yet on a schedule.
SOC 2 for VibeLock itself
Our own controls are mapped against the criteria. An audit is a separate and expensive undertaking, and nothing about it has been commissioned. This concerns VibeLock the company: the product is an application-level tool and does not cover SOC 2 for customers, now or later.
Why this page exists

A security vendor that publishes only its strengths is asking to be trusted on the parts it chose to disclose. The second list is the one that carries weight, because no vendor is obliged to publish it.