Your API keys and project data are protected through a zero-server-trust architecture. All sensitive data stays in your browser — never transmitted to or stored on Vibe-Coding Workflow servers.
We recommend using API keys with appropriate spending limits and permissions. For Gemini, use a project-scoped key. For OpenAI, set a monthly spending limit. For Anthropic, use workspace keys with usage limits. Never share your browser session with untrusted parties while your API keys are stored.
If you discover a security vulnerability, please report it through our contact form or open a security advisory on our GitHub repository. We take all security reports seriously and aim to respond within 48 hours.