Security and trust
Agents work on your real data. We treat that seriously.
Vibing runs on your documents, inboxes and business systems, so security is part of the product, not a page we wrote afterwards.
Hosting on Google Cloud
- Vibing runs on Google Cloud (Firebase, Cloud Run, Firestore, Cloud Storage, Cloud KMS, Secret Manager) in the United States.
- Google’s data centres, hardware and network are covered by its own independent audits, including SOC 2 Type II and ISO/IEC 27001, 27017 and 27018.
Encryption
- All traffic uses TLS. Databases, files and backups are encrypted at rest.
- Credentials for your connected systems are additionally encrypted with Cloud KMS keys that rotate automatically, and decrypted only when a run needs them.
- Our own service secrets live in Google Secret Manager, never in code.
Sign-in and access
- Two-step verification with authenticator apps (no SMS). Organizations can require it for every member.
- Organizations can require sign-in with their company Microsoft account and count their own Microsoft MFA.
- Roles inside each organization (owner, admin, builder, operator). Removing a member ends their sessions at once.
- Our staff use two-step verification on every system; access is reviewed quarterly and removed the day someone leaves.
Organizations kept apart
- Every request is checked against organization membership on our servers and again by database security rules, which are tested automatically.
- Items marked private are visible only to their owner.
How our AI is designed
- AI reads, judges and drafts; fixed, tested steps do the writing, so actions are repeatable and auditable.
- Anything irreversible or client-bound waits for a person to approve it.
- Content from outside (documents, emails, web pages) is treated as untrusted: agents do not follow instructions found inside it.
- We do not use your content to train AI models, and we choose AI providers whose business terms say the same.
Monitoring, logs and recovery
- Uptime checks and error alerts on every production service.
- An audit log of admin and security actions, kept for 400 days.
- Point-in-time recovery and daily backups; restores are tested. Recovery targets: back within 24 hours, losing at most 1 hour of data.
Compliance
- Security and privacy policies adopted in October 2026, with named security and privacy officers.
- A SOC 2 programme is under way. We will publish our report here when it is available.
- We support GDPR, UK GDPR, PIPEDA and Quebec’s Law 25. A data processing addendum is available for customers.
Need our security pack?
Policies, architecture, our subprocessor list, a data processing addendum and answers to your questionnaire. Ask during the demo or email us.