Operational rigor
Every approval flows through a circuit-breakered dispatch pipeline with exponential backoff, dead-letter persistence, and per-provider failure isolation. Operators can manually replay dead letters; nothing silently drops.
Trust Center
DataVibe is an AI Execution Security Gateway — every approval, dispatch, and policy change runs through audited, replayable infrastructure. This page tells security and compliance teams exactly how that works without requiring an NDA.
Certification transforms governance from internal tooling into externally verifiable trust. Workspaces that meet six deterministic criteria receive a public verification URL and embeddable badge for procurement and trust centers.
datavibe.cc/verify/[cert-id]Enterprise Shield (requires active certification) →Every approval flows through a circuit-breakered dispatch pipeline with exponential backoff, dead-letter persistence, and per-provider failure isolation. Operators can manually replay dead letters; nothing silently drops.
All inbound webhooks (Slack, HubSpot, Intercom, Teams, generic email intake) are HMAC-SHA256 verified with per-workspace secrets, a five-minute replay window, and constant-time comparison. Outbound webhooks ship X-Datavibe-Signature + X-Datavibe-Delivery-Id headers.
Workspace ownership is enforced at the database boundary on every read and write. A continuous tenant-isolation audit scans for orphan rows or cross-workspace references and surfaces findings to platform operators.
Every approval, rejection, dispatch, policy change, and assignment writes to an append-only audit log with actor + resource + IP attribution. Workspace owners can export the full log as JSON/NDJSON on demand (Pro+).
Real incidents are tracked first-class with root-cause, blast-radius, and resolution-notes fields. The /status page is wired off live data — uptime over rolling 90 days, open incidents, and component health update automatically.
Every gate decision is replayable. The flight recorder rebuilds the scanner timeline against any historical payload using the current published policy, enabling postmortems, compliance reviews, and policy tuning after the fact.
DataVibe publishes a formal governance coverage contract listing every enforced category, the exact rule IDs, severity semantics, adversarial test evidence, and explicit documented limitations. Governed categories are deterministically enforced and replay validated — not vague AI-safety claims.
We're transparent about where we are. We publish what's live, what's in audit, and what's on the roadmap so buyers can plan around real timelines.
Type I audit scoped Q3 2026; gap analysis complete.
Sustained-controls audit follows ~6 months after Type I.
Available on Enterprise once Type II is complete; PHI-grade dispatch providers required.
Roadmap dependency on SOC 2 Type II completion.
DPA addendum available on request. Data residency controls live for EU customers.
We use a small, deliberately chosen set of subprocessors. New subprocessors are announced 30 days in advance via email to all customer security contacts.
| Subprocessor | Purpose | Region |
|---|---|---|
| Vercel | Dashboard + landing site hosting (Edge + Node runtime) | Multi-region |
| Render | Core API service (Python FastAPI) | us-east / eu-west |
| Neon | Managed Postgres (workspaces, policies, audit log) | Customer-selectable |
| Cloudflare | DNS, WAF, edge cache, R2 for asset storage | Global |
| Stripe | Billing + subscription state | us-east / eu-west |
| Resend / SendGrid | Outbound notification email | us-east |
| Sentry | Application error monitoring (PII scrubbed) | us-west |
| Logtail / Better Stack | Structured log aggregation | us-east |
Every governance event is exportable as JSON/NDJSON for downstream SIEM ingestion.
Integration docs →Data Processing Addendum is available on request; HIPAA BAA shipping on Enterprise after Type II.
View DPA →Annual external pentest summary available to customers under MNDA.
Request summary →Real-time uptime, open incidents, and component health derived directly from our SystemEvent stream.
Open status page →