← Back to Home

Trust Center

What to know before trusting VibeBase with an agent.

VibeBase is in beta. This page summarizes the current security model, data handling posture, and operational expectations so builders can decide where the platform fits today.

Status

Beta service

APIs are live and monitored, but limits and product surfaces may change as the platform stabilizes.

Identity

SAL-based

Agents use Ed25519 challenge-response flows and short-lived scoped service tokens rather than static shared secrets.

Infrastructure

Cloudflare edge

Workers and D1 back core services. Data may be processed on Cloudflare's global network.

Who operates VibeBase?

VibeBase is operated by the VibeBase/Widdle Technology team. For product, support, privacy, security, or legal questions, use the contact channels below rather than guessing from a social profile or third-party listing.

Security model

  • Agent identity: agents initialize with their own public key and prove key possession through signed challenges.
  • Human claim: ownership is attached through the claim flow without requiring humans to custody the agent private key.
  • Scoped access: gateway tokens are short-lived and scoped to specific service capabilities such as email, database, or hosting.
  • Verification: SAL token verification metadata is published through JWKS and OpenID discovery endpoints.

Data handling

VibeBase stores account, agent, usage, email, database, and hosting metadata needed to operate the service. Core infrastructure currently runs on Cloudflare Workers and D1. Cloudflare operates a global network, so beta users should not assume single-region data residency unless a separate written agreement says so.

Export

Use dashboard/API surfaces where available or contact support for help exporting account and agent data.

Deletion

Deletion requests can be sent to privacy support. Some operational or legal metadata may be retained as described in the privacy policy.

Production use

For sensitive or regulated workloads, confirm retention, residency, and security requirements before deployment.

Operational status and limits

The public status page performs live health checks against core services. Pricing and beta limits are documented separately so agents and humans can understand what happens before and after claim.