Zero-Trust Privacy Standard

Privacy Policy

Last updated: January 2026

1. Core Architecture Guarantee

CoreVibbe is engineered under a zero-execution paradigm. Uploaded project archives (.zip) are extracted exclusively into temporary server memory. We never execute uploaded code, install npm/pip dependencies, run build scripts, or trigger arbitrary binaries.

2. Automatic Pre-AI Secret Redaction

Before any project information is processed by our rule engines or sent to Gemini AI for contextual analysis, our local sanitization engine scans for and redacts API keys, database connection strings, JWT secrets, passwords, and private key blocks.

3. Information We Collect

When creating an account, we store your email address, name, and a secure bcrypt hash of your password. We store generated audit metadata (framework, health score, finding summaries) when you explicitly save a report.

4. Your Data Rights

You have full ownership of your reports. You can delete saved audits at any time from your dashboard, which permanently removes the audit record from our PostgreSQL database.