Skip to content

Security

Security, Built Into Every Layer.

Vorx builds every app secure by default, encrypts your secrets, and keeps development and production apart — on every plan, without configuration.

Application security Data security Infrastructure security Pre-publish scan

Secured on every front

Independent layers of protection work together to reduce risk at every level.

Application security

Secure as it's built

Vorx builds your app secure by default — secrets stay server-side and every table is scoped by row-level security as the AI writes it — then runs a full security scan before every publish, so issues are caught before your users ever see them.

Data security

Locked down by default

Secrets are encrypted and never exposed to your code or the AI. Development and production are fully separated, and full version history means nothing is ever lost.

Infrastructure security

The same stack, whatever you pay

Every app runs isolated, behind a web application firewall with DDoS protection and encrypted storage. Every plan gets the same setup, including the free one, because running two standards would mean one of them is the worse one.

Pre-publish scan

Checked before you ship

Before every publish, Vorx re-checks your database's access rules for anything the public key could read or write, scans the built app for exposed secrets and credentials, and flags common XSS patterns in your source — the mistakes a generated app is most likely to make.

Your work stays yours

The things that matter most to your business never leave your control.

Never used to train models

Your code, prompts, and workspace data are never used to train Vorx or any provider's models. Contractual agreements restrict training and retention.

Choose where data lives

Your data lives on our managed infrastructure and doesn't move without you publishing a change. Ask us and we'll tell you exactly where it's hosted and who our providers are.

Isolated by design

Every workspace and project is logically separated at both the application and infrastructure layers. Your data is never accessible across accounts.

The controls you get today

We're an early-stage company, so we'd rather be straight with you about what exists now. Everything here is in the product today, on every plan.

Role-based access

Granular permissions for viewing, editing and publishing, so the right people have the right access.

Pre-publish security scan

Every app is scanned before it goes live, and issues are surfaced with the fix alongside them.

Secrets stay server-side

Keys and credentials are encrypted and never exposed to your app’s code or to the AI writing it.

Isolated workspaces

Every workspace and project is separated at both the application and infrastructure layer.

Shipping your first app? You're already covered.

Every app you build on Vorx gets the same protections as every other — from your very first publish, with nothing to configure.

  • A full security scan runs before every publish
  • Development and production data stay separated
  • Role-based access controls limit who can view, edit, or publish
  • Automatic backups mean you can always roll back

Talk to us about security

Need details for a vendor review or security questionnaire? We're happy to walk your team through how Vorx protects apps and data.

Encryption at rest
Isolated workspaces
Secrets stay server-side
Pre-publish security scan
Contact us about security

Frequently asked questions

Your data is hosted on our managed infrastructure and doesn't move without a change you publish. Contact us and we'll walk you through exactly where it lives and which providers handle it.

Every workspace and project is logically separated at both the application and infrastructure layers. Customer data is never accessible across accounts, and dev and production environments are kept apart.

Secrets are encrypted at rest and access-controlled by role. They're never exposed in plaintext in logs or interfaces, and they're never shared with the AI or embedded in your code.

Yes. A security scan runs automatically before every publish, re-checking your database's access rules for anything the public key could read or write, scanning the built app for exposed secrets and credentials, and flagging common XSS patterns in your source.

No. Your prompts, code, and workspace data are never used to train Vorx or third-party models. Where we work with AI providers, contractual agreements restrict training and retention of your data.

Yes. If you need details for a vendor review or security questionnaire, contact us and we'll walk you through our practices.

Know what you are shipping

Every app comes locked down by default. Read the code, check the rules, decide for yourself.