Skip to content

Security

Boundaries are part of the review.

VibeApprove is in private beta. These are the access, approval, and billing controls in the product today.

Access boundaries

Sign-in is handled by WorkOS AuthKit. Workspace access, review visibility, approval policy, and billing actions are checked on the server. GitHub and Slack credentials are used through their integration boundaries, and review approval remains an explicit human action.

Review and billing controls

Review requests are restricted by configured workspace and repository policy. Evidence is scoped to the reviewed commit. Approval and billing state are recorded as separate events, and credit is added only after a confirmed payment event. Prepaid AI calls reserve credit before they start; uncertain provider usage remains held until an operator reconciles it.

Responsible disclosure

If you find a security issue during the beta, use the support path on the support page or email the beta owner at manthan@ludicrous.io. Include the affected workflow, a safe reproduction, and whether any account or repository access was involved. Please do not include credentials or private tokens in the request.