Secure by design

Encryption everywhere, authentication you can trust, and code that always stays yours. Here’s exactly how we protect your work, and what’s still on the way.

Built on Clerk · Supabase · Apple sign-in · Codemagic

How we protect your work

Encryption everywhere

Every request runs over HTTPS/TLS, and your data is encrypted at rest in our Postgres database. Nothing about your account or your projects travels or sits in the clear.

Managed authentication

Sign-in, sessions, and passwords are handled by Clerk, an audited authentication provider. We never see or store your password.

Your Apple key stays encrypted

Your App Store Connect key is encrypted and used only to sign your builds. It never leaves our server or appears in logs.

Your data and your code

You own everything

Every app is a full, standard Xcode project you can download at any time, signed under your own Apple account. No lock-in, no proprietary format, no middleman holding the keys.

Not used to train models

We don't use your prompts, code, or projects to train models. Your work stays your work.

Access and deletion

Under GDPR you can export your data or permanently delete your account and everything tied to it, at any time.

Privacy and isolation

Privacy you control

Granular cookie consent with a preferences center you can change anytime, a clear privacy policy, and a lawful basis for the limited data we process. You always know what we hold and why.

Secrets never hardcoded

API keys live in server-side environment variables, never in the client or the codebase, and never in version control.

Isolation by account

Your projects are scoped to your account and enforced server-side, so your data is never accessible across users.

Compliance, honestly

GDPR
Aligned today
SOC 2
In progress
Encryption
In transit & at rest

We only list what’s true today. Formal SOC 2 attestation and enterprise controls like SSO, SAML, and audit logs are on our roadmap, and we’d rather earn the badge than borrow it.

Frequently asked questions

Your account and project data live in a managed Postgres database (Supabase), encrypted at rest, and are served to you only over HTTPS/TLS.

No. We don't use your prompts, code, or projects to train models. When we work with AI providers, calls are made to generate your app, not to build a training set from your work.

Yes. Your App Store Connect API key is encrypted and stored server-side. It's used only to sign your builds and ship them to your TestFlight, and it never appears in logs or the client.

Yes, anytime. From Settings, the account page lets you permanently delete your account and everything tied to it. Any active paid subscription is canceled as part of that.

You do, completely. Every app is a full Xcode project you can download, signed under your own Apple account. No lock-in, no royalties.

Not yet. Enterprise single sign-on is on our roadmap for teams. We'd rather tell you what's true today than claim a control we haven't built.

Email security@vynbe.com with the details. We read every report and will get back to you quickly.

Found something, or have a question?

Reach the team directly. We take every security report seriously.

Email security@vynbe.com

See also our Privacy Policy and Terms.