Vibe Coding Agency

Trust

Security & trust

How we handle data, access, infrastructure, and compliance for AI engineering work. No marketing promises — just what is actually in place.

Data handling

  • We do not train models on client code or data.
  • Prefer local-first tools (UltraWork Coder, RegicideOS) where code never leaves your machine.
  • Cloud-hosted work uses your accounts and keys whenever possible.
  • NDA-bound engagements on request.

Access controls

  • Self-hosted Pocket ID for authentication where possible.
  • Least-privilege access for all infrastructure.
  • Encrypted tunnels (cloudflared) for remote services.
  • Short-lived credentials; no long-lived secrets committed to repositories.

Infrastructure

  • Static site on Cloudflare Pages with Functions.
  • Reproducible CI/CD via Dagger.
  • Backend services on Fly.io.
  • GPU workloads run on premium neocloud providers with no contracts.

Compliance posture

We are not SOC 2 or ISO 27001 certified today. For most engagements we work inside your environment, under your policies, and sign whatever NDA or BAU terms you need. If a formal compliance boundary is required, we can scope that explicitly.

What we can provide

  • Signed NDAs and confidentiality agreements
  • Architecture and data-flow documentation
  • Security questionnaires answered directly by the engineer doing the work
  • Honest limitation statements (no pretend certifications)

Report a security issue

If you find a vulnerability in anything we run or ship, email us. We will respond within one business day and keep you informed as we fix it.

Email [email protected]

Questions?

We will answer security questionnaires, walk through architecture, and provide references under NDA.

Start a security conversation

Newsletter

Notes from the edge

Field notes on AI engineering, security, and performance. No spam.