Vibe Construction Suite Security Policy

Version
1.0
Effective Date
August 2, 2026
Last Updated
August 2, 2026

See also the Terms of Service, Privacy Policy, Acceptable Use Policy, and Data Retention & Account Deletion Policy.


This Security Policy ("Policy") describes the administrative, technical, and organizational safeguards that Vibe Supply Products LLC ("Company," "we," "our," or "us") applies to the Vibe Construction Suite platform, including the Hub, all associated applications and modules, websites, and related services (collectively, the "Services").

This Policy applies to every individual or entity that uses the Services, including trial accounts, active subscribers, and administrators ("Customer" or "you"). It is maintained by Vibe Supply Products LLC to answer common security questions about the Vibe Construction Suite.

THIS POLICY DESCRIBES SECURITY PRACTICES. IT IS NOT A CERTIFICATION, AUDIT REPORT, WARRANTY, OR GUARANTEE OF SECURITY OUTCOMES.

1. PURPOSE

The purpose of this Policy is to describe, in plain terms, how the Company approaches the security of the Services, which safeguards are applied, how responsibility is divided between the Company and its Customers, and how security concerns and suspected vulnerabilities should be reported.

This Policy is incorporated by reference into, and forms part of, the Vibe Construction Suite Terms of Service, and supplements the Privacy Policy, Acceptable Use Policy, and Data Retention & Account Deletion Policy. Capitalized terms not defined here have the meanings given to them in the Terms of Service.

2. SECURITY PHILOSOPHY

Vibe Supply Products LLC implements commercially reasonable administrative, technical, and organizational safeguards designed to protect Customer information.

The Company's approach favors defense in depth, least-privilege access, secure defaults, and reliance on established, professionally operated infrastructure providers rather than bespoke security implementations. Security is treated as an ongoing operational practice that evolves alongside the Services rather than a one-time configuration.

Security measures may include, where applicable:

  • encrypted communications;
  • authenticated user access;
  • role-based permissions;
  • secure cloud hosting;
  • audit logging;
  • system monitoring;
  • routine backups; and
  • security updates.

The specific safeguards applied to any given feature depend on the nature of that feature and may change over time as the Services and the threat landscape evolve.

3. NO GUARANTEE OF ABSOLUTE SECURITY

No internet-connected system can guarantee absolute security. Accordingly, the Company does not warrant that unauthorized access, cyberattacks, data breaches, or other security incidents can never occur.

The Company's obligation is to apply commercially reasonable safeguards and to respond diligently to security issues, not to achieve a guaranteed outcome. Nothing in this Policy creates a warranty, guarantee, service level, or representation beyond those expressly stated in the Terms of Service, and the limitations of liability and disclaimers in the Terms of Service apply in full to this Policy.

4. SHARED RESPONSIBILITY MODEL

Security of the Services is a shared responsibility among the underlying infrastructure providers, the Company, and the Customer. Each layer depends on the layers around it.

  • Infrastructure providers are responsible for the security of the physical facilities, hardware, network fabric, and managed platform services on which the Services run.
  • The Company is responsible for the secure design, configuration, deployment, and operation of the Vibe Construction Suite application layer, including authentication, access controls, permissions, and data handling within the platform.
  • The Customer is responsible for the security of its own accounts, credentials, devices, networks, users, and the decisions it makes about who may access its data and at what permission level.

No safeguard implemented by the Company can protect an account whose credentials have been shared, reused, or compromised on the Customer's side.

5. ACCOUNT SECURITY

Access to the Services requires an authenticated account. Accounts are associated with a verified email address and belong to a company workspace, and access to company data is scoped to the members of that company.

Sessions are tracked so that administrators can review active access to their company account. The Company may expire, revoke, or require re-authentication of sessions where necessary to protect the account or the platform.

Customers should not share login credentials with unauthorized users. Each licensed user should maintain an individual account.

Shared or generic accounts undermine audit logging, permission enforcement, and incident investigation, and may violate the Acceptable Use Policy and applicable licensing terms.

6. PASSWORD SECURITY

Account passwords are handled by the platform's managed authentication service. Passwords are stored using industry-standard one-way cryptographic hashing and are never stored, transmitted, or displayed by the Company in plain text. Company personnel cannot retrieve a Customer's password.

Password reset is performed through a verified email flow. Customers are responsible for choosing strong, unique passwords, for not reusing passwords across unrelated services, and for updating a password promptly if they believe it may have been exposed.

7. AUTHENTICATION

The Services support authentication by email and password and by supported third-party sign-in providers. New accounts are subject to email verification, and invited users are provisioned through a verified invitation flow issued by a company administrator.

Where a user moves between Vibe Construction Suite applications, access is authorized by the Hub through short-lived, single-use launch credentials rather than by re-entering long-lived credentials in each application. The Hub is the authority for identity, licensing, and application access across the Suite.

Authentication capabilities may be extended over time. Any additional authentication options will be described in the Services and, where material, reflected in a revision to this Policy.

8. ACCESS CONTROLS

Access to Customer data is controlled at the data layer as well as the application layer. Database access is subject to row-level authorization rules that scope records to the company that owns them, so that a user authenticated to one company cannot read or modify another company's records.

Administrative access by Company personnel is limited to those individuals who require it to operate, support, and secure the platform, and is used only for those purposes — for example, to investigate a reported issue, respond to a support request, or address a security or availability incident.

Internal credentials, API keys, and service secrets are stored in managed secret storage and are not embedded in client-side application code.

9. ROLE-BASED PERMISSIONS

Within a company workspace, capabilities are governed by roles. Roles determine which users may manage the company profile, invite or remove members, assign application licenses and seats, manage billing, configure notifications, and access administrative areas of the Hub.

Roles and permissions are enforced on the server side and are stored separately from user profile records so that a user cannot elevate their own privileges by editing their own profile. Application access is additionally gated by licensing: a user must hold an assigned entitlement, or the company must hold an active trial, in order to launch a licensed application.

Company owners and administrators are responsible for assigning the least level of access each user requires and for removing access promptly when a user leaves the organization or changes responsibilities.

10. DATA ENCRYPTION

Communications between Customer devices and the Services are encrypted in transit using industry-standard Transport Layer Security (HTTPS). Communications between platform components and managed backend services are likewise encrypted in transit.

Data stored in the platform's managed database and file storage is encrypted at rest by the underlying cloud infrastructure providers using industry-standard encryption.

The Company does not offer, and this Policy does not claim, end-to-end encryption in which the Company is unable to access Customer content. Access to Customer content by Company personnel is restricted as described in Section 8 and governed by the Privacy Policy.

11. CLOUD INFRASTRUCTURE

The Services are hosted on managed, professionally operated cloud infrastructure. The Company does not operate its own physical data centers. Physical security, hardware maintenance, facility access control, and environmental controls are the responsibility of the infrastructure providers described in Section 17.

Application code is deployed through an automated build and deployment pipeline. Production configuration and secrets are managed separately from application source code.

12. NETWORK SECURITY

Public endpoints of the Services are served over encrypted connections. Backend data access is mediated by authenticated, authorization-enforcing interfaces rather than by direct, publicly reachable database connections.

Publicly callable endpoints — such as webhook receivers and integration callbacks — are designed to verify the identity or signature of the caller before processing a request. The underlying infrastructure providers apply network-level protections, including transport termination and denial-of-service mitigation, at the edge.

13. LOGGING AND MONITORING

The Services record activity and audit logs covering significant account and administrative events, including membership and role changes, license and seat assignments, session activity, and integration events. Company administrators can review activity relevant to their own company within the Hub.

The Company also collects operational and diagnostic telemetry — such as error reports, request logs, and platform health signals — to detect failures, investigate incidents, and maintain the reliability and integrity of the Services.

Logs are retained for the periods described in the Data Retention & Account Deletion Policy, are access-restricted, and are handled in accordance with the Privacy Policy.

14. BACKUP AND DISASTER RECOVERY

The Services rely on routine, automated backup and disaster recovery processes provided by the platform's managed infrastructure, designed to protect against data loss, corruption, and service interruption. Backups are created and rotated automatically on a recurring schedule and are access-restricted.

Backups exist for disaster recovery and platform integrity purposes. They are not a per-customer, per-project, or per-file undelete service, and the Company does not guarantee that deleted data can be restored. Retention, deletion, restoration limitations, and Customer export responsibilities are governed by the Data Retention & Account Deletion Policy.

15. VULNERABILITY MANAGEMENT

The Company maintains the Services on actively supported platform versions and applies security updates to the application and its dependencies as part of routine maintenance. Automated checks are used to identify known vulnerable dependencies and insecure configurations, and identified issues are prioritized according to severity and exposure.

Managed infrastructure components — including hosting, database, authentication, and storage services — are patched by the respective providers as part of their managed service obligations.

The Company does not publish the details, counts, or status of specific internal findings. Remediation timelines depend on severity, exploitability, and the availability of a fix from upstream providers.

16. INCIDENT RESPONSE

Security incidents will be investigated promptly. Where legally required, affected Customers will receive notice consistent with applicable law.

Upon becoming aware of a suspected security incident, the Company will work to contain the issue, assess its scope and impact, preserve relevant records, remediate the underlying cause, and take reasonable steps to prevent recurrence. Notice, where required, will be provided without undue delay and will describe the nature of the incident and the steps taken to the extent then known.

The Company may temporarily suspend access, in whole or in part, where necessary to:

  • protect Customer data;
  • investigate suspected security incidents;
  • prevent fraud; or
  • maintain platform integrity.

Where practicable, the Company will provide notice of such a suspension and will restore access once the underlying issue is resolved. The Company may cooperate with law enforcement or governmental authorities when legally required.

17. THIRD-PARTY SERVICE PROVIDERS

Portions of the Services rely upon trusted third-party providers. Depending on the features in use, these may include providers of cloud hosting and application delivery, managed database and file storage, authentication and identity services, mapping and address lookup services, payment processing, transactional and notification email delivery, and artificial intelligence services.

Those providers maintain their own security practices, certifications, and privacy policies, and their handling of information is governed by their own terms. The Company selects providers it considers reputable and appropriate for the purpose, shares only the information necessary for the provider to perform its function, and remains responsible for its own configuration and use of those services.

The Company does not control, and does not warrant, the security practices of third-party providers. Additional detail about how information is shared with providers is set out in the Privacy Policy.

18. CUSTOMER SECURITY RESPONSIBILITIES

Customers are responsible for:

  • maintaining secure passwords;
  • protecting account credentials;
  • securing devices used to access the Services; and
  • promptly reporting suspected unauthorized access.

Customers are further responsible for keeping their operating systems and browsers current, for granting each user only the access that user requires, for removing access promptly when a user leaves the organization, for reviewing active sessions and activity logs available in the Hub, and for exporting and retaining any records they need in accordance with the Data Retention & Account Deletion Policy.

Suspected unauthorized access, credential compromise, or other security concerns should be reported immediately to admin@vibeconstructionsuite.com.

19. RESPONSIBLE SECURITY DISCLOSURE

Responsible security researchers are encouraged to privately report suspected vulnerabilities.

Suspected vulnerabilities should be reported to admin@vibeconstructionsuite.com with sufficient detail to reproduce and assess the issue. The Company asks that researchers allow a reasonable period to investigate and remediate before any public disclosure.

The Company requests that researchers:

  • avoid disrupting, degrading, or overloading production systems;
  • avoid accessing, downloading, modifying, or destroying Customer data;
  • use only test accounts and test data created for the purpose;
  • refrain from social engineering, phishing, or physical intrusion; and
  • refrain from public disclosure until the issue has been resolved.

Testing that stays within these guidelines and is reported in good faith will be treated as authorized for the purposes of the Acceptable Use Policy. The Company does not currently operate a paid bug bounty program, and no compensation is offered or implied.

20. POLICY UPDATES

The Company may revise this Policy from time to time to reflect changes in the Services, in operational and security practices, or in applicable law. When material changes are made, the Company will publish the revised Policy with an updated version number and Last Updated date and, where appropriate, provide additional notice through the Services or by email.

Each published version of this Policy is retained as a distinct, versioned document. Revisions apply prospectively from the date they take effect.

21. CONTACT INFORMATION

Security questions, incident reports, suspected unauthorized access, and responsible vulnerability disclosures should be directed to:

  • Vibe Supply Products LLC
  • Vibe Construction Suite
  • Email: admin@vibeconstructionsuite.com

© Vibe Supply Products LLC. All rights reserved. Vibe Construction Suite is a product of Vibe Supply Products LLC.