Skip to content
VibeProtect
What we check
Lovable Replit Bolt Cursor
Pricing MCP Sign in Scan free

legal

Terms of Service

Last updated October 1, 2026

1. Who we are

VibeProtect is operated by Instant City Solutions LLC, a Florida limited liability company based in Miami, Florida. In these terms, "we", "us" and "our" mean Instant City Solutions LLC, and "you" means the person or organization using the service at vibeprotect.dev.

By creating an account or using VibeProtect, you agree to these terms. If you are agreeing on behalf of a company, you confirm you have authority to bind it.

2. What the service does

VibeProtect checks web applications, including applications built with AI app builders, for security problems, and suggests fixes. It offers two kinds of scan:

  • Live app scans of an application you have verified. These load the application's pages and the JavaScript they include, read HTTP response headers, and complete TLS handshakes, in the same way an ordinary visitor's browser would.
  • Repository scans of source code repositories you have connected through our GitHub App. These read the repository's files to look for committed secrets, dependencies with published vulnerabilities, database rules that allow public access, and risky code patterns. Repository code is never executed.

Each finding may include a suggested prompt for an AI coding tool. Suggested prompts are starting points: you are responsible for reviewing any change an AI tool makes in response.

VibeProtect does not attempt exploitation, fuzzing, password guessing, authentication as any user, or any test designed to alter, disrupt, or gain access to a system.

3. Your account

You must provide an accurate email address and keep your password confidential. You are responsible for everything that happens under your account, including actions taken by team members you invite and by API keys or AI agents you connect. Tell us promptly at support@vibeprotect.dev if you believe your account has been compromised. You must be at least 18 years old.

4. Authorization to scan

This is the most important section in these terms. Scanning systems you do not control may be unlawful where you or they are, and we take the boundary seriously.

  • You may only scan applications that you own or are expressly authorized in writing to test. Before an application can be scanned, you must prove control of its exact hostname by one of the methods we offer: serving a file we generate at /.well-known/vibeprotect.txt, adding a meta tag we generate to its home page, or, on a domain you control, publishing a DNS TXT record we generate.
  • Verification covers only the exact hostname verified (and its www. counterpart), not other hostnames on the same domain or platform.
  • We re-check proofs periodically. If a proof stops being published, the application is automatically returned to unverified and scanning stops.
  • You represent and warrant that, for every application you verify and every repository you connect, you hold the necessary authority to have it tested, including from any hosting provider, platform or other third party whose systems are involved.
  • You must not attempt to bypass or interfere with verification, and you must not verify an application on behalf of someone who has not authorized the testing.
  • You are solely responsible for the consequences of scanning any application you verify.

If we believe an application is being scanned without authorization, we may suspend scanning, remove the application, or terminate the account immediately and without notice. Report suspected misuse to security@vibeprotect.dev.

5. Backend services your application uses

Many applications built with AI app builders store their data in a hosted backend such as Supabase or Firebase, and publish that backend's address and public client key in the application's own JavaScript. Today VibeProtect checks such backends only through the configuration files in repositories you connect. If a live app scan ever checks a backend that a verified application's public code identifies, it will do so only within these limits:

  • Only the backend project identified by the verified application's own public code is contacted.
  • Only read-only requests are sent, using only the public keys the application itself publishes. Where a request could return records, it is limited to a single record.
  • The scanner never writes, changes or deletes data, never signs up or signs in as a user, and never uses a privileged or secret key, even if it finds one exposed.
  • We record what is reachable (for example, table and column names and a count), never the contents of records.

By verifying an application, you confirm that you are authorized to have the backend services it uses checked in this way.

6. Acceptable use

You agree not to:

  • Use the service to scan, probe, or gather information about applications, backends or repositories you are not authorized to test.
  • Use findings, including exposed keys or readable data, to access systems or data you are not authorized to access.
  • Resell or provide the service to third parties without our written agreement.
  • Attempt to circumvent plan limits, rate limits, or access controls, or to access another customer's data.
  • Use the service, its API or its MCP server to violate any applicable law, or to plan or support an attack on any system.
  • Interfere with the operation of the service, including by automated means beyond documented API and MCP usage.

7. Plans and billing

  • The Free plan costs nothing and has the limits shown on the pricing page. Paid plans are billed in advance through Stripe, monthly or yearly depending on the term you choose. We do not receive or store your full card details.
  • You can cancel at any time from the billing page. Cancellation takes effect at the end of the current billing period, and you keep paid features until then. Yearly terms are not refunded pro rata when cancelled mid-term.
  • Fees already paid are non-refundable except where required by law, though we will consider reasonable requests sent to support@vibeprotect.dev.
  • We may change pricing with at least 30 days' notice to the email on your account. Continuing to use a paid plan after the change takes effect means you accept the new price.
  • Plan limits (applications, scans per month, scan frequency, team seats) are enforced by the service. Reaching a limit never incurs an overage charge; the action is declined until you upgrade or the period resets.

8. Your data and findings

You retain ownership of your applications, your code and the scan results generated for your account. We use your data to operate and improve the service as described in our Privacy Policy. We do not sell your scan results, and we do not disclose findings about your applications to third parties except as described in that policy or as required by law.

9. No guarantee of security

VibeProtect reports what it can observe at a point in time, from outside your application and in the repositories you connect. A clean result or a good grade does not mean an application is secure. The service does not find every kind of vulnerability, and it cannot see systems, code or configuration it has no access to.

Findings, grades and suggested prompts are informational. You are responsible for deciding what to act on, for reviewing changes made by you or by an AI tool, and for testing them. VibeProtect is not a substitute for a penetration test, a security audit, or professional advice.

10. Availability and alerts

We aim to keep the service available but do not promise uninterrupted operation. We may modify, suspend, or discontinue features, and maintenance can cause downtime. Scheduled scans and alert delivery may be delayed, skipped, or fail. You should not rely on VibeProtect alerts as your only safeguard for any critical event.

11. Disclaimers and limitation of liability

The service is provided "as is" and "as available". To the fullest extent permitted by law, we disclaim all warranties, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement.

To the fullest extent permitted by law, Instant City Solutions LLC will not be liable for any indirect, incidental, special, consequential, or punitive damages, or for lost profits, revenue, data, or goodwill. Our total aggregate liability arising out of or relating to the service will not exceed the greater of one hundred US dollars ($100) or the amount you paid us in the twelve months before the event giving rise to the claim.

12. Indemnification

You will indemnify and hold harmless Instant City Solutions LLC and its members, officers and employees from any claim, loss, liability, or expense (including reasonable legal fees) arising from your use of the service, your breach of these terms, or, in particular, any scan you initiate against an application, backend or repository you were not authorized to test.

13. Suspension and termination

You may close your account at any time. We may suspend or terminate your access if you breach these terms, if your payment fails and is not cured, or if we reasonably believe your use creates legal risk or harms others. On termination, your right to use the service ends; data handling after termination is described in the Privacy Policy.

14. Changes to these terms

We may update these terms. If a change is material, we will notify the email on your account at least 14 days before it takes effect. Continuing to use the service after that means you accept the updated terms.

15. Governing law

These terms are governed by the laws of the State of Florida, without regard to its conflict-of-laws rules. The state and federal courts located in Miami-Dade County, Florida have exclusive jurisdiction over any dispute, and you consent to their personal jurisdiction and venue.

16. General

If any provision is held unenforceable, the rest remains in effect. Our failure to enforce a provision is not a waiver of it. You may not assign these terms without our consent; we may assign them in connection with a merger, acquisition, or sale of assets. These terms, together with the Privacy Policy, are the entire agreement between us regarding the service.

17. Contact

Instant City Solutions LLC
Miami, Florida, United States
support@vibeprotect.dev

VibeProtect

Security checks for apps you built by prompting. Made in Miami by Instant City Solutions LLC.

Product
What we check Pricing Verifying your app MCP server
Built with
Lovable Replit Bolt Cursor
Company
Support About our scanner Terms Privacy Report abuse
© 2026 Instant City Solutions LLC we only scan apps you prove you own