Secure by design
Encryption everywhere, authentication you can trust, and code that always stays yours. Here’s exactly how we protect your work, and what’s still on the way.
Built on Clerk · Supabase · Apple sign-in · Codemagic
How we protect your work
Encryption everywhere
Every request runs over HTTPS/TLS, and your data is encrypted at rest in our Postgres database. Nothing about your account or your projects travels or sits in the clear.
Managed authentication
Sign-in, sessions, and passwords are handled by Clerk, an audited authentication provider. We never see or store your password.
Your Apple key stays encrypted
Your App Store Connect key is encrypted and used only to sign your builds. It never leaves our server or appears in logs.
Your data and your code
You own everything
Every app is a full, standard Xcode project you can download at any time, signed under your own Apple account. No lock-in, no proprietary format, no middleman holding the keys.
Not used to train models
We don't use your prompts, code, or projects to train models. Your work stays your work.
Access and deletion
Under GDPR you can export your data or permanently delete your account and everything tied to it, at any time.
Privacy and isolation
Privacy you control
Granular cookie consent with a preferences center you can change anytime, a clear privacy policy, and a lawful basis for the limited data we process. You always know what we hold and why.
Secrets never hardcoded
API keys live in server-side environment variables, never in the client or the codebase, and never in version control.
Isolation by account
Your projects are scoped to your account and enforced server-side, so your data is never accessible across users.
Compliance, honestly
We only list what’s true today. Formal SOC 2 attestation and enterprise controls like SSO, SAML, and audit logs are on our roadmap, and we’d rather earn the badge than borrow it.
Frequently asked questions
Your account and project data live in a managed Postgres database (Supabase), encrypted at rest, and are served to you only over HTTPS/TLS.
No. We don't use your prompts, code, or projects to train models. When we work with AI providers, calls are made to generate your app, not to build a training set from your work.
Yes. Your App Store Connect API key is encrypted and stored server-side. It's used only to sign your builds and ship them to your TestFlight, and it never appears in logs or the client.
Yes, anytime. From Settings, the account page lets you permanently delete your account and everything tied to it. Any active paid subscription is canceled as part of that.
You do, completely. Every app is a full Xcode project you can download, signed under your own Apple account. No lock-in, no royalties.
Not yet. Enterprise single sign-on is on our roadmap for teams. We'd rather tell you what's true today than claim a control we haven't built.
Email security@vynbe.com with the details. We read every report and will get back to you quickly.
Found something, or have a question?
Reach the team directly. We take every security report seriously.
Email security@vynbe.comSee also our Privacy Policy and Terms.