The vibe app rating system
The trust layer for AI-built apps
You built it fast. VibefyCode tells you — with evidence — what a first real user, an app store reviewer, or someone poking at your API would find. Then, if it earns one, you get a mark you can put on your site that we take down again if it stops being true.
This is the mark you earn
Issued only after a person has reviewed the assessment. Every one carries a signature anybody can check, and a page anybody can open — including the people you are trying to persuade.
ActiveIt says one thing, precisely
That this application was assessed against a published rubric version, on a stated date, and met the published threshold. Not that it is free of defects, and not that it is a security audit.
It can be checked by a stranger
The badge carries a signature and a public identifier. Anybody can open its verification page and see the score, the date, and whether it is still in force.
It comes down when it stops being true
On a continuous plan the application is re-assessed. A material regression suspends the badge automatically, and the customer is told what changed and why.
And what it looks like when it is not in force
Suspended
Expired
Revoked
Where it sits on your site
One line of HTML in your footer. It links to the verification page, so a visitor who does not believe it can find out in one click — which is the only reason a mark like this is worth anything.
A fictional application, used so the example demonstrates the badge rather than endorsing anybody.
What gets assessed
Rubric v1.1.0, published in full. Scores are computed from versioned data, not from a private judgement.
Functional integrity
25%Do the core flows actually complete, and does the app behave when they do not?
Security posture
25%What is observably exposed, and does authorisation hold on the server?
Data & privacy practice
15%What is collected, is it disclosed, and can a user get out?
Practicality & UX
15%Can a first-time user get to value, on the device they actually own?
Production readiness
10%Would this survive contact with real traffic and a bad day?
Store & distribution readiness
10%Would this pass the published submission requirements on first attempt?
How it works
- 01
Prove you control it
Publish a DNS record or a file at a known path. Nothing is tested until that check passes — for your protection and ours.
- 02
The assessment runs
Inside the scope you authorised, under a request ceiling and a spend ceiling. Every observation is captured as evidence.
- 03
A person reviews it
A reviewer checks the findings against the evidence before anything is published. No badge is issued without that step.
- 04
The badge stays honest
On a continuous plan the application is re-assessed. If it drifts materially, the badge is suspended and you are told why.