Loading VibeLux...
Loading VibeLux...
VibeLux is an early-stage company, and we take protecting your data seriously from day one. This page describes the practices in place today. We don’t claim certifications we haven’t earned — if you have specific compliance requirements, get in touch and we’ll tell you exactly where we stand.
Sign-in and account management are handled by Clerk. Access to your data requires an authenticated session, and every API request is scoped to the signed-in user and their facility — so one organization’s data is never reachable by another.
All traffic to and from VibeLux is served over HTTPS/TLS. Payment details are entered directly into Stripe’s PCI-compliant fields — VibeLux never sees or stores card numbers.
The application runs on Vercel; data is stored in managed Postgres (Neon), with uploaded files in cloud object storage. We rely on these providers’ encryption-at-rest and physical-security controls rather than operating our own servers.
Sensitive actions — billing events, admin changes, and compliance records — are written to durable, timestamped logs so activity can be reviewed.
Data is partitioned per facility/organization. Queries are filtered by the caller’s membership, and admin tooling is gated to a small, explicit allowlist.
If you believe you’ve found a security issue, please email us before disclosing it publicly. We read every report and will work with you on a fix.
Email security@vibelux.ai (or contact us). Please give us a chance to respond before public disclosure.