Your app stays yours.

Selling a security check with an opaque security posture would be absurd. This page says plainly what we do with your application and your data.

We require your authorisation before scanning

A check only starts after you confirm, at checkout, that you own the application or have explicit authorisation from its owner. We record that confirmation with the order. Developers, agencies and consultants can run checks on behalf of the owner.

We don't need your source code

Checks run against the deployed application only. Read-only repository access may be offered later as an optional add-on for deeper analysis. It will never be required.

We don't modify your application

Every check is non-destructive. We do not create, update or delete records, we do not submit real payments, and we do not run denial-of-service style tests.

Your findings are private

Reports are visible only to the account that ordered the check. We do not sell or share findings. Aggregated, anonymised statistics may be published for research and never identify an application.

Data retention

Scan evidence and reports are kept for 90 days after the check so you can run the included verification re-scan and download the report. You can request earlier deletion at any time.

Encryption

Data is encrypted in transit and at rest. Access to scan infrastructure is limited to the people who operate it, with audited access.

Subprocessors

A current list of the hosting, payment and email providers we rely on is published here and updated before any change takes effect.

Responsible disclosure

If you find a security issue in VibeGuard itself, we want to hear about it. Write to the security contact below. We acknowledge reports within two working days and do not pursue researchers acting in good faith.

Security contact

Questions, deletion requests and vulnerability reports: security@vibeguard.tech