Skip to content
VibefyCode

The vibe app rating system

The trust layer for AI-built apps

You built it fast. VibefyCode tells you — with evidence — what a first real user, an app store reviewer, or someone poking at your API would find. Then, if it earns one, you get a mark you can put on your site that we take down again if it stops being true.

This is the mark you earn

Issued only after a person has reviewed the assessment. Every one carries a signature anybody can check, and a page anybody can open — including the people you are trying to persuade.

The Verified by VibefyCode badgeActive
  • It says one thing, precisely

    That this application was assessed against a published rubric version, on a stated date, and met the published threshold. Not that it is free of defects, and not that it is a security audit.

  • It can be checked by a stranger

    The badge carries a signature and a public identifier. Anybody can open its verification page and see the score, the date, and whether it is still in force.

  • It comes down when it stops being true

    On a continuous plan the application is re-assessed. A material regression suspends the badge automatically, and the customer is told what changed and why.

And what it looks like when it is not in force

  • The badge in its suspended stateSuspended
  • The badge in its expired stateExpired
  • The badge in its revoked stateRevoked

Where it sits on your site

One line of HTML in your footer. It links to the verification page, so a visitor who does not believe it can find out in one click — which is the only reason a mark like this is worth anything.

https://kettle.example

A fictional application, used so the example demonstrates the badge rather than endorsing anybody.

6Scored dimensions
v1.1.0Rubric in force
100%Findings carrying evidence

What gets assessed

Rubric v1.1.0, published in full. Scores are computed from versioned data, not from a private judgement.

  • Functional integrity

    25%

    Do the core flows actually complete, and does the app behave when they do not?

  • Security posture

    25%

    What is observably exposed, and does authorisation hold on the server?

  • Data & privacy practice

    15%

    What is collected, is it disclosed, and can a user get out?

  • Practicality & UX

    15%

    Can a first-time user get to value, on the device they actually own?

  • Production readiness

    10%

    Would this survive contact with real traffic and a bad day?

  • Store & distribution readiness

    10%

    Would this pass the published submission requirements on first attempt?

How it works

  1. 01

    Prove you control it

    Publish a DNS record or a file at a known path. Nothing is tested until that check passes — for your protection and ours.

  2. 02

    The assessment runs

    Inside the scope you authorised, under a request ceiling and a spend ceiling. Every observation is captured as evidence.

  3. 03

    A person reviews it

    A reviewer checks the findings against the evidence before anything is published. No badge is issued without that step.

  4. 04

    The badge stays honest

    On a continuous plan the application is re-assessed. If it drifts materially, the badge is suspended and you are told why.

What a VibefyCode assessment is not

It is not a penetration test, a security audit, a code audit, a legal or regulatory certification, or a guarantee of any kind. It does not certify that an application is free of defects, lawful, or fit for any particular purpose. The mark means one thing: this app was assessed against the published rubric, on a stated date, and met the published threshold.