A sustainical platform · First security review is on us

Vibe coding made building software easy.
We make running it safe.

VanillaVibe takes the applications your teams build with AI tools and puts them into secure, continuously reviewed production — in days, not months — then keeps them there. Built on the engineering practice behind sustainical's AI and cloud platforms.

Reviewed continuously. Operated around the clock. Yours entirely.

First review complimentary · Read-and-issues-only access, revocable at any moment · Or start with a simple upload

The production gap

The app is finished. Then nothing happens.

Teams everywhere vibe-code internal applications — forecasting tools, trackers, workflow apps — in days instead of quarters. Then it runs on a laptop, or it quietly reaches production with no security review, no identity integration, no backups, and no one responsible for keeping it alive.

IT departments don't want these apps in their environment. Companies without IT departments have nowhere to put them at all. The creativity is real, the gap is real — and AI-generated code demonstrably carries more security issues than hand-written code. It is reaching production anyway.

Who it is for

However your organisation is set up.

What you need from us depends on who runs software where you work. What stays the same: somebody built something good, and it deserves to survive.

01

You have an IT team with standards

They will say yes to these applications — under real governance, integrated with the company login and the monitoring they already run, with a clear line of responsibility.

You get evidence — reproducible reports and audit trails your IT team can verify for themselves.

02

Your IT team is already at capacity

They are running the systems the company depends on. Internal apps built by other teams are genuinely not what their week has room for.

You get relief — no tickets, no on-call burden. IT tends to approve it because it takes work away.

03

You have no IT operations at all

You need the thing to simply work, without anyone on your side learning what it is called underneath or making decisions they have no basis for.

You get simplicity — no infrastructure vocabulary, no configuration, one dashboard that reads in plain language.

Your team already built the thing. We make sure it is still running in three years.

No rewrite, no framework of ours, no handover. The application stays yours — we take on everything around it.

How a customer experiences it

Four steps from laptop to permanent production.

The environment adapts to the application, never the reverse. No prescribed frameworks, no builder lock-in, no technical decisions pushed onto you.

STEP 01

Discover

First insight: the same day

Everything starts with a conversation, not a scan. We walk through your applications: the ideas behind them, who uses them, which data and systems they touch, what "important" means for each one.

That conversation produces the shared picture everything downstream is configured from — and it is where the free review of a first application is agreed.

STEP 02

Analyze

Findings within days

The application undergoes adversarial and security reviews producing prioritized, evidence-linked findings — filed as work items directly into your own repository, phrased so your AI agents can execute them.

Fix, re-review, repeat. Each iteration produces a reproducible Trust Score report that works as compliance evidence. In parallel, your dedicated enclave is provisioned automatically — infrastructure is never the critical path.

STEP 03

Roll out

One to three days

The application moves into the prepared environment — hosted by us or inside your own infrastructure. Employees sign in with the company login they already have: authentication sits in front of every application, so the apps carry no login code at all.

That removes the single most common vulnerability class in AI-generated software. Where the app needs internal data, a small connector opens an encrypted tunnel. Every application is isolated from every other.

STEP 04

Keep running

Incident to resolution: minutes

Every subsequent change flows through the same review and deployment loop, continuously. Critical findings block a release; everything else ships and stays visible.

Incidents are detected around the clock, triaged, and resolved in minutes — from a strictly bounded set of permitted actions, every one of them audit-logged. People remain accountable for the outcome, and where you need a guaranteed human response, that is contractual.

Same day
To first security insight
1–3 days
From application to production
Minutes
From merged change to deployment
24/7
Monitored and recovered, day and night

Start with one application and see what happens.

The first review costs you nothing and commits you to nothing. Read-and-issues-only access, revocable whenever you like — or upload a snapshot and grant nothing at all.

What holds it together

One standard, applied the same way every time.

You never size, configure, or choose anything. That is the point.

What sets us apart

Most platforms hand these applications back. We take them.

An internal app built in a week does not fit anywhere: too important to run on a laptop, too unfamiliar for IT to adopt, too small to justify a project. We built VanillaVibe for exactly that gap — production engineering and security review, packaged so a team without an operations department can use it.

One ruleset

A single definition of what "secure" means powers the reviews, the release gates, and the operational checks alike. There is no way for the platform to contradict itself between stages.

One hardened template

Every customer receives their own isolated environment, stamped from one continuously hardened template. Improvements reach all customers at once, while isolation stays absolute per customer.

One app definition

Generous enough that the typical internal application never notices its boundaries. You never size, configure, or choose infrastructure — because there is nothing to choose.

Plain-language dashboards

Availability, deployment history, requests and errors, active users, resource trends, security status, backup health. A department head can read it; an IT lead can additionally pipe the raw feeds into their own monitoring.

Trust, by construction

You hand over the most sensitive thing you have.

So trust is not a marketing promise here. It is a set of verifiable properties.

Access is minimal and revocable

Narrowly scoped, read-and-issues-only credentials you grant and can revoke at any moment. Or start with a simple upload and grant nothing.

Nothing leaves the perimeter

Your own isolated environment. Analysis runs on open-weight models hosted in-region, with zero-data-retention terms where a frontier model is required.

Code is never reused

Contractually, your code and data are processed solely to deliver the service. Never for training, never for other customers.

Read all six verifiable properties, including exit and audit →

Want to see this on your own code?

Send us one application. You get prioritised findings, filed in your own repository, and a Trust Score you can re-run after fixing.

Where it runs

One platform.
Configured per region.

Data residency, identity federation, and compliance evidence are per-region configurations of the same platform — which makes a new market a distribution question, not an engineering one.

In-region inference

AI analysis runs on cost-efficient open-weight models hosted in-region. Where a frontier model is ever required, only under strict zero-data-retention terms.

Open-weight · Zero data retention

Evidence that fits your market

Each Trust Score report is reproducible and mapped to whatever regulatory framework applies where you operate — usable directly as compliance evidence.

Reproducible · Audit-ready

Delivered through partners

IT service providers resell VanillaVibe to the client base that already trusts them — the same platform, the same evidence, under an existing relationship.

Partner network

Complimentary security review

Find out what you are sitting on.

We review one of your applications and give you the findings — with no charge and no obligation. You grant read-and-issues-only access, and the findings land in your own repository as work items your coding agents can pick up immediately.

Grant or upload

Connect a repository with narrowly scoped, read-and-issues-only credentials — or upload a snapshot if you'd rather grant nothing yet.

~2 minutes

We review it

Adversarial and security review against the same ruleset that later gates your releases — nothing special-cased for the demo.

Hours, not weeks

Evidence linked

Every finding is tied to a file, a line, and a reproduction path — so nothing arrives as an unverifiable assertion.

Same day

Filed as work items

Findings are written into your repository, phrased so Claude Code, Codex, or your agent of choice can act on them directly.

Your repo

Trust Score report

A reproducible score you can re-run after fixing. Improvement is the evidence — and it works toward your regulatory framework.

Re-runnable
Why we offer it

You should see the problem before you buy the solution.

Nobody can judge this platform from a description. So we do the first review at our own cost and hand you the findings — a concrete account of one real application, whether or not you take it further.

If the report shows your application is already in good shape, that is a perfectly good outcome and we will tell you so. If it shows what we usually find, you will know exactly what you are dealing with.

What you get back

A report you can act on the same week:

  • Prioritised findings, each tied to a file, a line, and a way to reproduce it
  • Work items filed in your own repository, written for your coding agents to execute
  • A Trust Score you can re-run after fixing, so the improvement is on record
  • Yours to keep and share internally — no obligation attached
One dashboard

Everything your teams shipped, in plain language.

No infrastructure vocabulary anywhere. A department head can read it without a glossary — and an IT lead can pipe the same raw feeds into the monitoring they already run.

sustainical · VanillaVibe Illustrative — sample data
Availability
99.98%
All 7 apps healthy
Security status
0 critical
3 low · none blocking
Trust Score
88/100
+6 this quarter
Backups
Healthy
Verified 2h ago
Active users across all applications
1,284
Last deployment
4 min ago
forecasting-app · v1.24
Resource trend
Growing
Well inside your envelope

Availability · deployment history · requests and errors · active users · resource trends · security status · backup health

Building blocks

The pieces your app needs, run for you.

Most internal applications need the same few things behind them. Sign-in is part of every plan. The rest you can bring yourself — or add ours and never think about it again.

Included on every plan

Identity & access

Sign-in sits in front of every application, so your apps carry no login code at all. Connects to Microsoft Entra ID, Google Workspace, Okta or any SAML/OIDC provider you already run.

Add-on

Application data

A managed database with file storage, instant APIs and realtime updates — the backend most vibe-coded apps assume exists. Backed up nightly, reachable only from inside your environment.

Add-on

Workflow automation

Visual automation for the work around your app — scheduled jobs, approvals, notifications, moving data between systems. Runs on your side of the boundary.

See what "operated" means, and what else we can run for you →

Not sure which of your applications belongs here?

That is what the first conversation is for. We walk through what your teams have built and tell you honestly which ones fit — and which ones do not.

Pricing

You pay per application and stage. Nothing else.

No separate platform fee. Setup, onboarding, identity, security review and round-the-clock operations are all in the price of the applications you run.

Starter

One application, live

You built something and it needs a real home.

249/month

1 application · 1 stage
€2,988 billed annually

See what is included
MOST CHOSEN Growth

Several apps, promoted properly

More than one team building, with changes worth trying first.

749/month

5 applications · up to 3 stages each
€8,988 billed annually

See what is included
Enterprise

In your own environment

For organisations that cannot host outside their own perimeter.

Let's talk

Unlimited applications and stages
Runs in your cloud or data centre

Talk to sustainical

Service levels from 9×5 to 24×7 with one-hour resolution · infrastructure envelope per stage · optional components
See full pricing, service levels and what is included →

Three ways to start.

Whether you want proof on a real application, a conversation about your portfolio first, or a regional delivery route — we meet you where you are.

Product proof

Complimentary security review

Submit one real application. You get prioritized, evidence-linked findings and a reproducible Trust Score report — before any commitment, and with credentials you can revoke.

Submit a repository →
Discovery

Talk through your portfolio

A working session with our engineers on what your teams have built, who uses it, and which systems it touches — and where a first review makes sense.

Book a discovery session
Regional fit

Talk to our regional team

Discuss data residency, identity federation, and rollout in your market — including delivery through sustainical's partner network of IT service providers.

Talk to our regional team →

Your team already built it. Let's make sure it survives.

Send us one application and we will tell you exactly what you are dealing with. The first review is on us, and the report is yours either way.

Read-and-issues-only access · Revocable at any moment · Or start with a simple upload

A sustainical platform.