Skip to content
Security and trust

Agents work on your real data. We treat that seriously.

Vibing runs on your documents, inboxes and business systems, so security is part of the product, not a page we wrote afterwards.

Hosting on Google Cloud

  • Vibing runs on Google Cloud (Firebase, Cloud Run, Firestore, Cloud Storage, Cloud KMS, Secret Manager) in the United States.
  • Google’s data centres, hardware and network are covered by its own independent audits, including SOC 2 Type II and ISO/IEC 27001, 27017 and 27018.

Encryption

  • All traffic uses TLS. Databases, files and backups are encrypted at rest.
  • Credentials for your connected systems are additionally encrypted with Cloud KMS keys that rotate automatically, and decrypted only when a run needs them.
  • Our own service secrets live in Google Secret Manager, never in code.

Sign-in and access

  • Two-step verification with authenticator apps (no SMS). Organizations can require it for every member.
  • Organizations can require sign-in with their company Microsoft account and count their own Microsoft MFA.
  • Roles inside each organization (owner, admin, builder, operator). Removing a member ends their sessions at once.
  • Our staff use two-step verification on every system; access is reviewed quarterly and removed the day someone leaves.

Organizations kept apart

  • Every request is checked against organization membership on our servers and again by database security rules, which are tested automatically.
  • Items marked private are visible only to their owner.

How our AI is designed

  • AI reads, judges and drafts; fixed, tested steps do the writing, so actions are repeatable and auditable.
  • Anything irreversible or client-bound waits for a person to approve it.
  • Content from outside (documents, emails, web pages) is treated as untrusted: agents do not follow instructions found inside it.
  • We do not use your content to train AI models, and we choose AI providers whose business terms say the same.

Monitoring, logs and recovery

  • Uptime checks and error alerts on every production service.
  • An audit log of admin and security actions, kept for 400 days.
  • Point-in-time recovery and daily backups; restores are tested. Recovery targets: back within 24 hours, losing at most 1 hour of data.

Compliance

  • Security and privacy policies adopted in October 2026, with named security and privacy officers.
  • A SOC 2 programme is under way. We will publish our report here when it is available.
  • We support GDPR, UK GDPR, PIPEDA and Quebec’s Law 25. A data processing addendum is available for customers.

Need our security pack?

Policies, architecture, our subprocessor list, a data processing addendum and answers to your questionnaire. Ask during the demo or email us.