Skip to main content
DataVibe
AlphaSolutionsPricingResearchDocsAbout
Log inBook a demoRequest API Access

Trust Center

How DataVibe earns the trust enterprises require.

DataVibe is an AI Execution Security Gateway, every approval, dispatch, and policy change runs through audited, replayable infrastructure. This page tells security and compliance teams exactly how that works without requiring an NDA.

DataVibe Certified AI Governance

Certification transforms governance from internal tooling into externally verifiable trust. Workspaces that meet six deterministic criteria receive a public verification URL and embeddable badge for procurement and trust centers.

  • 90+ days of production gate traffic
  • Zero unresolved BLOCK violations in the last 30 days
  • Intact audit chain and custom governance policy authored
  • 95%+ SLA compliance and tested legal-hold infrastructure
Public verify URL: datavibe.cc/verify/[cert-id]Enterprise Shield (requires active certification) →

Operational rigor

Every approval flows through a circuit-breakered dispatch pipeline with exponential backoff, dead-letter persistence, and per-provider failure isolation. Operators can manually replay dead letters; nothing silently drops.

  • Architecture overview →

Cryptographic verifiability

All inbound webhooks (Slack, HubSpot, Intercom, Teams, generic email intake) are HMAC-SHA256 verified with per-workspace secrets, a five-minute replay window, and constant-time comparison. Outbound webhooks ship X-Datavibe-Signature + X-Datavibe-Delivery-Id headers.

Multi-tenant isolation

Workspace ownership is enforced at the database boundary on every read and write. A continuous tenant-isolation audit scans for orphan rows or cross-workspace references and surfaces findings to platform operators.

Immutable audit trail

Every approval, rejection, dispatch, policy change, and assignment writes to an append-only audit log with actor + resource + IP attribution. Workspace owners can export the full log as JSON/NDJSON on demand (Pro+).

  • Security policy →

Incident response

Real incidents are tracked first-class with root-cause, blast-radius, and resolution-notes fields. The /status page is wired off live data, uptime over rolling 90 days, open incidents, and component health update automatically.

  • Live status →

AI governance forensics

Every gate decision is replayable. The flight recorder rebuilds the scanner timeline against any historical payload using the current published policy, enabling postmortems, compliance reviews, and policy tuning after the fact.

Governed category contract

DataVibe publishes a formal governance coverage contract listing every enforced category, the exact rule IDs, severity semantics, adversarial test evidence, and explicit documented limitations. Governed categories are deterministically enforced and replay validated, not vague AI-safety claims.

  • Governance model →
  • Integration docs →

Standards control matrix

Security reviews should not have to infer how an AI governance platform maps to modern assurance frameworks. DataVibe exposes the control family, runtime enforcement point, and evidence artifact for each standard.

StandardRuntime coverageEvidence artifact
OWASP LLM Top 10Prompt-injection, sensitive-data disclosure, excessive-agency, supply-chain, and model-output handling controls.Deterministic rule IDs, scanner timeline, blocked/queued decision reason, audit replay.
NIST AI RMFGovern, Map, Measure, and Manage mapped to policy authoring, risk scoring, human review, and post-incident tuning.Policy snapshots, config hash, reviewer decisions, remediation notes, exported governance reports.
ISO/IEC 42001AI management-system controls for roles, lifecycle governance, risk treatment, monitoring, and continuous improvement.Workspace roles, change approvals, versioned policies, incidents, and management-review exports.
EU AI ActHuman oversight, transparency, logging, technical documentation, and high-risk workflow evidence.Article 14 review queue, Article 13 explanations, immutable logs, certification readiness checklist.
SOC 2 TSCSecurity, availability, confidentiality, processing integrity, and privacy evidence for AI dispatch controls.Access logs, tenant isolation checks, HMAC webhooks, DLQ/replay records, uptime and incident history.

Certifications & compliance roadmap

We're transparent about where we are. We publish what's live, what's in audit, and what's on the roadmap so buyers can plan around real timelines.

  • SOC 2 Type I

    Type I audit scoped Q3 2026; gap analysis complete.

    In progress
  • SOC 2 Type II

    Sustained-controls audit follows ~6 months after Type I.

    On roadmap
  • HIPAA BAA

    Available on Enterprise once Type II is complete; PHI-grade dispatch providers required.

    On roadmap
  • ISO 27001

    Roadmap dependency on SOC 2 Type II completion.

    On roadmap
  • GDPR + UK DPA + India DPDPA

    DPA addendum on request. Self-service data export and account deletion in Dashboard Settings (30-day grace). Grievance: [email protected].

    Live

Procurement evidence checklist

Buyers should not have to chase vague trust claims. These are the artifacts DataVibe can produce for security review, vendor risk management, and regulated-customer due diligence.

SOC 2 evidence package

Requestable (Type I in progress)

Control list, management assertion draft, governance audit sample, and audit-chain export. Full attestation pending Type I completion.

Open artifact →

Security architecture pack

Public

Auth boundaries, webhook signing, SSRF protections, tenant isolation, and release checks.

Open artifact →

DPA and subprocessor register

Public + requestable

Data processing terms, subprocessors, residency posture, and audit-access language.

Open artifact →

Operational status evidence

Public

Live incident posture, component health, rolling uptime, and post-incident traceability.

Open artifact →

Policy coverage contract

Public

Governed categories, rule IDs, severity semantics, adversarial test evidence, and limitations.

Open artifact →

Subprocessors

We use a small, deliberately chosen set of subprocessors. Material additions are logged in our subprocessor register; Enterprise customers receive 30 days' advance notice via their security contact.

SubprocessorPurposeRegion
VercelDashboard + landing site hosting (Edge + Node runtime)Multi-region
RenderCore API service (Python FastAPI)us-east / eu-west
NeonManaged Postgres (workspaces, policies, audit log)Customer-selectable
CloudflareDNS, WAF, edge cache, R2 for asset storageGlobal
StripeBilling + subscription stateus-east / eu-west
Resend / SendGridOutbound notification emailus-east
SentryApplication error monitoring (PII scrubbed)us-west
Logtail / Better StackStructured log aggregationus-east

Audit log export

Every governance event is exportable as JSON/NDJSON for downstream SIEM ingestion.

Integration docs →

GDPR / DPDPA self-service

Authenticated users can export their data or schedule account deletion from Dashboard Settings. No ticket required.

Open Settings →

DPA / BAA

Data Processing Addendum is available on request; HIPAA BAA shipping on Enterprise after Type II.

View DPA →

Penetration test summary

Annual external pentest summary available to customers under MNDA.

Request summary →

Live operational status

Real-time uptime, open incidents, and component health derived directly from our SystemEvent stream.

Open status page →

Questions for the security or compliance team? Email [email protected]. We acknowledge within one business day.

Enterprise tier (post-pilot): workspace SSO/OIDC, private Core API region, async semantic scanner tier. Contact [email protected] for roadmap timing.

DataVibe

DataVibe sits between your AI systems and business operations. Runtime policy gates, human oversight, immutable evidence, public certification, and Enterprise Shield coverage for valid claims.

Need help? Use our contact form.

Product

AlphaAgentic AIEU AI ActEnterprise ShieldGovernancePricing

Resources

Integration guideBlogCase studiesChangelog

Company

AboutContactStatusSecurity

Legal

TermsPrivacyDPASLA

Get started

Request API accessBook a demoContact

© 2026 DataVibe

Trust centerStatusArchitecturePrivacy policySecurityTerms of useCookie policyDPA