We build the platform so that everything is locked down by default. The server your AI agent creates is invisible from the internet. By default, only you have access to your app. Keys are issued with limited permissions. You stay the owner of your data and decide who can see what.
One step blocks 99% of account-takeover attempts. Takes a minute to turn on.
It opens everything you have access to. Never paste it into code, never share it in chats.
It means full access from the internet with no sign-in. Do not enable it unless you understand the consequences.
Three parties are involved when you work with the platform. Each has its own zone. This helps clarify what we take on and what depends on you.
This is a third-party service. Code from any AI is worth reviewing - that is common industry practice, not a Vibecode quirk.
Works without your involvement and protects you by default.
By default every server starts in non-public mode - all ports closed, no access from outside. Only those you grant access to can reach the server, and only through an encrypted tunnel.
Every app is available only to its owner by default. Widening access is step-by-step: employees, department, the whole Bitrix24 account. Every change is logged.
Data is protected in transit over a secure channel and at rest. Keys to third-party services are stored encrypted.
Vibecode servers run on Bitrix24 Cloud. Vibecode is part of the Bitrix24 ecosystem.
Sign-in is designed so that secret session data never reaches the visitor’s browser. Attempts to impersonate someone are cut off right at the entry point.
You can limit permissions, set an expiration date, turn on read-only mode (where nothing can be changed or deleted), and revoke a key at any time.
To let an AI agent start building an app for you, you issue it the unified Vibecode key and pass it to an external tool. In effect this key is the master pass to everything you have access to. Whoever holds the key controls the access. Treat it more carefully than an ordinary password.
A stolen key means access to your data. Through it an attacker can run AI requests and burn through your balance - sometimes before you even notice.
Revoke it in the interface, create a new one, update the apps that use it, and review the request log for unfamiliar addresses.
Six simple actions. No programming skills required.
Most accounts are lost not because of holes in platforms, but because of weak passwords and stolen credentials. We start here.
This is the most important rule of vibe coding, and here is why.
AI tools are third-party services. Before pasting anything into a prompt, think about what exactly you are sending.
Good news for those who cannot read code: you can delegate the review to an AI. The bad news - you cannot delegate it to the same agent that wrote the app: it tends to "justify" its own work and may convincingly say everything is fine even when it is not.
If you are not sure, it is always best to entrust the app’s security audit to an information-security specialist or a company that provides such services.
When the app is ready, decide who should use it and set access on the "no more than needed" principle.
Planning to put the app in a catalog or let others use it? Then you become its author and must attach your own terms of use and privacy policy, compliant with applicable law, so that a person cannot start using the app without agreeing to the terms.
The most open access mode is called "Public". Before enabling it, it is important to understand exactly what happens.
The server never switches to public mode on its own - only after your explicit confirmation, and every such change is recorded in the log.
Turn on "Public" only when you truly need to - for example, for a publicly available form or landing page that has no sensitive data and no write access to your Bitrix24 account. If in doubt, do not enable it. Opening access later is always easier than dealing with the aftermath of a leak.
These things apply to any AI tool, including Vibecode. There is no way around them.
Whatever it does counts as your actions. If, because of overly broad permissions or an unclear prompt, the agent does something undesirable, you are the one responsible. So keep permissions minimal and stay in control.
An attacker can slip a hidden command inside a page, document or email that the AI reads. This is called prompt injection: the model sees an "outside" instruction and sometimes follows it. The defense is simple - give the agent minimal permissions and do not connect unnecessary external sources.
Generated text and code may not match the facts - the AI can "invent" a feature or get the logic wrong. Review the result and do not trust important decisions with legal or financial consequences to AI alone - the final word stays with a human.
The platform’s built-in BitrixGPT model runs within our perimeter and does not use your data for its training. Your prompts are processed only to answer the specific request and do not enter the training set.
If you connect third-party AI services through your own key (BYOK), that service’s policy is on the provider’s side. The terms of use are worth reading with the specific service.
Some risks are removed not by a setting but by attention - we try to help you keep it.
Risky actions require confirmation. Turning on "Public" mode, issuing a new key with broad permissions, changing two-factor sign-in settings - in each case we show exactly what will happen and ask you to confirm.
We try to notify you by email about critical operations and suspicious sign-in attempts. If you receive an email about an action you did not take, that is a reason to check your account right away and change your password if needed.
Copy them, go through the items, and you will head off most problems in advance.
Phishing is an attempt to extract a password or data through fake emails and sites. It is the most common and effective way to break in - and it is easy to spot once you know the signs.
For example, bltrix instead of bitrix, a zero instead of the letter "O", an extra hyphen.
"Urgent", "or access gets blocked today", "5 minutes left".
Real services do not do this. Open the site manually via a bookmark.
Files like .exe, .scr or with a double extension such as document.pdf.exe.
In doubt - do not follow a link from the email. Open the service manually via a bookmark or a search box. Confirm a request for money or data through another channel - a phone call or a work chat.
No jargon. If something on the page is unclear, the explanation is probably here.
Sign-in in two steps: a password plus a one-time code.
The master pass you issue to AI agents. It opens access to everything you have access to.
What exactly the pass is allowed to do - for example, only read the CRM.
A command hidden in text that can trick the AI.
"Bring your own key" - using your personal key to a third-party AI service.
The one who decides what data about people to collect and why (when it comes to your customers, that is you).
Vibecode servers with no public internet address - closed by default, reachable only through an encrypted tunnel.
Access to the app from the internet with no sign-in, for any visitor.
A calm, fast plan for three cases.
Change your password, turn on 2FA, revoke suspicious keys and sign out of all sessions. Then report it to support through the feedback form. The faster, the better.
Excess access, strange behavior, an unexpected bill for AI requests - narrow the access policy or temporarily switch the app to read-only mode, revoke excess permissions from the agent and keys, and check the access log.
Please report it to us promptly through the feedback form in your account. Do not disclose the vulnerability publicly until it is fixed - for our part, we will try to respond promptly.
For help, write to us through the feedback form in your account - it is the fastest channel.