Operational rigor
Every approval flows through a circuit-breakered dispatch pipeline with exponential backoff, dead-letter persistence, and per-provider failure isolation. Operators can manually replay dead letters; nothing silently drops.
Trust Center
DataVibe is an AI Execution Security Gateway, every approval, dispatch, and policy change runs through audited, replayable infrastructure. This page tells security and compliance teams exactly how that works without requiring an NDA.
Certification transforms governance from internal tooling into externally verifiable trust. Workspaces that meet six deterministic criteria receive a public verification URL and embeddable badge for procurement and trust centers.
datavibe.cc/verify/[cert-id]Enterprise Shield (requires active certification) →Every approval flows through a circuit-breakered dispatch pipeline with exponential backoff, dead-letter persistence, and per-provider failure isolation. Operators can manually replay dead letters; nothing silently drops.
All inbound webhooks (Slack, HubSpot, Intercom, Teams, generic email intake) are HMAC-SHA256 verified with per-workspace secrets, a five-minute replay window, and constant-time comparison. Outbound webhooks ship X-Datavibe-Signature + X-Datavibe-Delivery-Id headers.
Workspace ownership is enforced at the database boundary on every read and write. A continuous tenant-isolation audit scans for orphan rows or cross-workspace references and surfaces findings to platform operators.
Every approval, rejection, dispatch, policy change, and assignment writes to an append-only audit log with actor + resource + IP attribution. Workspace owners can export the full log as JSON/NDJSON on demand (Pro+).
Real incidents are tracked first-class with root-cause, blast-radius, and resolution-notes fields. The /status page is wired off live data, uptime over rolling 90 days, open incidents, and component health update automatically.
Every gate decision is replayable. The flight recorder rebuilds the scanner timeline against any historical payload using the current published policy, enabling postmortems, compliance reviews, and policy tuning after the fact.
DataVibe publishes a formal governance coverage contract listing every enforced category, the exact rule IDs, severity semantics, adversarial test evidence, and explicit documented limitations. Governed categories are deterministically enforced and replay validated, not vague AI-safety claims.
Security reviews should not have to infer how an AI governance platform maps to modern assurance frameworks. DataVibe exposes the control family, runtime enforcement point, and evidence artifact for each standard.
| Standard | Runtime coverage | Evidence artifact |
|---|---|---|
| OWASP LLM Top 10 | Prompt-injection, sensitive-data disclosure, excessive-agency, supply-chain, and model-output handling controls. | Deterministic rule IDs, scanner timeline, blocked/queued decision reason, audit replay. |
| NIST AI RMF | Govern, Map, Measure, and Manage mapped to policy authoring, risk scoring, human review, and post-incident tuning. | Policy snapshots, config hash, reviewer decisions, remediation notes, exported governance reports. |
| ISO/IEC 42001 | AI management-system controls for roles, lifecycle governance, risk treatment, monitoring, and continuous improvement. | Workspace roles, change approvals, versioned policies, incidents, and management-review exports. |
| EU AI Act | Human oversight, transparency, logging, technical documentation, and high-risk workflow evidence. | Article 14 review queue, Article 13 explanations, immutable logs, certification readiness checklist. |
| SOC 2 TSC | Security, availability, confidentiality, processing integrity, and privacy evidence for AI dispatch controls. | Access logs, tenant isolation checks, HMAC webhooks, DLQ/replay records, uptime and incident history. |
We're transparent about where we are. We publish what's live, what's in audit, and what's on the roadmap so buyers can plan around real timelines.
Type I audit scoped Q3 2026; gap analysis complete.
Sustained-controls audit follows ~6 months after Type I.
Available on Enterprise once Type II is complete; PHI-grade dispatch providers required.
Roadmap dependency on SOC 2 Type II completion.
DPA addendum on request. Self-service data export and account deletion in Dashboard Settings (30-day grace). Grievance: [email protected].
Buyers should not have to chase vague trust claims. These are the artifacts DataVibe can produce for security review, vendor risk management, and regulated-customer due diligence.
Control list, management assertion draft, governance audit sample, and audit-chain export. Full attestation pending Type I completion.
Open artifact →Auth boundaries, webhook signing, SSRF protections, tenant isolation, and release checks.
Open artifact →Data processing terms, subprocessors, residency posture, and audit-access language.
Open artifact →Live incident posture, component health, rolling uptime, and post-incident traceability.
Open artifact →Governed categories, rule IDs, severity semantics, adversarial test evidence, and limitations.
Open artifact →We use a small, deliberately chosen set of subprocessors. Material additions are logged in our subprocessor register; Enterprise customers receive 30 days' advance notice via their security contact.
| Subprocessor | Purpose | Region |
|---|---|---|
| Vercel | Dashboard + landing site hosting (Edge + Node runtime) | Multi-region |
| Render | Core API service (Python FastAPI) | us-east / eu-west |
| Neon | Managed Postgres (workspaces, policies, audit log) | Customer-selectable |
| Cloudflare | DNS, WAF, edge cache, R2 for asset storage | Global |
| Stripe | Billing + subscription state | us-east / eu-west |
| Resend / SendGrid | Outbound notification email | us-east |
| Sentry | Application error monitoring (PII scrubbed) | us-west |
| Logtail / Better Stack | Structured log aggregation | us-east |
Every governance event is exportable as JSON/NDJSON for downstream SIEM ingestion.
Integration docs →Authenticated users can export their data or schedule account deletion from Dashboard Settings. No ticket required.
Open Settings →Data Processing Addendum is available on request; HIPAA BAA shipping on Enterprise after Type II.
View DPA →Annual external pentest summary available to customers under MNDA.
Request summary →Real-time uptime, open incidents, and component health derived directly from our SystemEvent stream.
Open status page →