Trust

Security at VibeLock

VibeLock produces a Trust Center for every customer that lists only what is proven. This is our own, computed by the platform from evidence it observed in our app and our code, in the same format a customer's page takes.

Security at VibeLock

VibeLock LLC · Newest verification within 24 hours

67 verified

by VibeLock's own tests
What was verifiedCatalogue 1.0.0
  • ASVS Level 1the minimum set, as OWASP defines it40 verified
  • ASVS Level 2the recommended set21 verified
  • LegalGDPR and EU AI Act articles6 verified
  • AdvisoryOWASP Top 10 for LLM Applications0 verified
  • Live URL18
  • Repository3
  • Coding tool34
  • Cross-check4
  • Provider-owned8
Requirements our controls satisfyControls verified
  • OWASP ASVS 5.0

    Application security verification

    61%
  • GDPR

    Application-level articles

    6%
  • EU AI Act

    Application-level articles

    0%
Verified controls67 verified
  • Authentication and access control

    20 verified
    • Row-level access policies on every table holding user data
    • Every object access ownership-checked on the server
    • Admin routes enforce a server-side role check
    • Sessions have an inactivity timeout and an absolute lifetime
  • Secrets, data and transit

    17 verified
    • No secrets in the served bundle or the repository
    • API key values never stored, submitted code never logged
    • HSTS, a Content-Security-Policy and TLS 1.2 or later on every response
    • Deletion and export routes verified end to end
  • Input, logic, API and configuration

    24 verified
    • Every API route guarded; CORS restricted to one origin
    • Server-side validation on every write
    • Rate limiting on authentication and public writes
    • No dependency alert open on the repository host
  • Governance

    6 verified
    • Privacy policy promises match verified controls
    • Sub-processors named match the actual stack
    • Incident runbook names our real components
    • Privacy policy published and reachable
Subprocessors
ServicePurposeLocation
Hosted database and authenticationDatabase and authenticationUnited States
Application hostingApplication hostingUnited States
Model providerPolicy and threat model generationUnited States
Payment processorPaymentsUnited States
Transactional emailTransactional emailUnited States
Verified by VibeLock from evidence observed at a stated commit, against OWASP ASVS 5.0 and the application-level articles of the GDPR and the EU AI Act · methodology 1.0.0 · not a third party certification or audit

Supporting documentation

A Trust Center is only meaningful if the method behind it is published. Ours is.

Reporting an inaccuracy security@vibelock.ai