What we commit to, and what we have not done yet
VibeLock holds the security posture of other people’s projects. If it were breached it would expose exactly the material its customers were trying to organise, so every practice the product asks for has to hold here first.
True today
Controls that are implemented and verifiable today, rather than intentions written in the present tense.
- Data minimisation
- API key values, submitted code, plaintext passwords, health data and card numbers are never stored. Data that is never collected cannot be exposed.
- Multi factor authentication on production systems
- Required on every third party account that can reach customer data or deploy code.
- Disclosure programme
- Open from before launch. Acknowledgement within 24 hours, a resolution timeline within 72, and no legal action against researchers acting in good faith.
- Published legal documents
- Terms, privacy policy, data processing addendum, subprocessor list and acceptable use, all public rather than available on request.
- Breach notification commitment
- Affected users notified within 72 hours of confirming a breach, running from awareness rather than from the end of an investigation.
- Our own posture published
- The trust page shows what is in place and what is outstanding, including the items we have not done.
Still ahead
Listed without target dates. A date attached to a commitment that cannot yet be met is a claim, not a plan.
- Independent penetration test
- Before general availability. No firm has been engaged yet, and we will name them here once one has been.
- Our own Trust Center, published
- Computed by the same method customers get, from real evidence, with no exception for us. It publishes when the platform does.
- First full incident drill
- The playbook is documented. Executing it end to end is a separate exercise, and has not yet been carried out.
- Documented retention schedule
- Retention is currently described in the privacy policy but not yet held as a separate operational schedule.
- Formal access review
- Least privilege is applied when access is granted. A recurring review of who still holds what is not yet on a schedule.
- SOC 2 for VibeLock itself
- Our own controls are mapped against the criteria. An audit is a separate and expensive undertaking, and nothing about it has been commissioned. This concerns VibeLock the company: the product is an application-level tool and does not cover SOC 2 for customers, now or later.
A security vendor that publishes only its strengths is asking to be trusted on the parts it chose to disclose. The second list is the one that carries weight, because no vendor is obliged to publish it.