Vibey trust center
Security by isolation and control
Vibey is designed to keep each merchant, brand, agent, credential, browser profile, and knowledge vault separated.
Last updated: 5 September 2026
Access control
Merchant access is authenticated through Shopify. Tenant and brand scope is enforced server-side; browser input never chooses its own authorization boundary.
Credentials
OAuth tokens and provider credentials are encrypted and brokered server-side. They are not displayed to agents, stored in browser storage, or placed in an Obsidian Brain.
Controlled actions
Customer-support output remains draft-only. Shopify publication requires explicit human approval of the exact revision. Destructive and permission-expanding actions are denied by default.
Reporting
Report suspected vulnerabilities to contact@getconsultingonline.com without customer data or active credentials.