Trust starts with clear boundaries.
Valibrio uses layered access controls and server-side safeguards to protect creator workspaces, participant feedback, stored assets, billing flows, and AI-assisted decision briefs.
Protection model
How Valibrio approaches security.
Security controls are applied across application authorization, database access, storage, public response submission, billing, and privileged server operations.
Workspace and data isolation
Creator data is protected through authentication, ownership checks, and database row level security. Access rules scope validations and their response data to the appropriate owner.
Controlled response submission
Participant responses are created through server-side submission flows. Validation status, submitted steps, answer requirements, and referenced validation data are checked before a response is accepted.
Abuse and duplicate controls
Public response submission uses rate limiting, spam checks, and duplicate-response detection. Rate-limit and participant fingerprint keys are stored as SHA-256 hashes rather than raw IP address and user-agent combinations.
Owner-scoped storage access
Storage access for creator assets is restricted through authenticated, owner-scoped policies. File operations are tied to the authenticated user's storage path.
Server-only privileged access
Privileged credentials used for trusted database operations are restricted to server-side code and are not persisted in browser sessions.
Public validation boundaries
Shareable validation access is controlled by validation state. Response submission separately verifies that the validation is currently allowed to accept responses.
Payments through Stripe
Checkout, subscriptions, invoices, and payment methods are handled through Stripe. Valibrio does not directly store payment card details.
AI-assisted decision briefs
Decision briefs are generated from collected validation data and participant responses. Access to generation and stored results is subject to application and database authorization controls.
Principles
Security is layered.
Valibrio combines ownership checks, database policies, storage controls, server-side validation, and abuse protections so security does not depend on a single boundary.
Least necessary access
Authenticated and privileged operations are separated so elevated database access is reserved for trusted server-side workflows.
Layered authorization
Application ownership checks work alongside database and storage policies rather than relying on a single access-control layer.
Defence against misuse
Public participation remains simple while server-side validation, rate limiting, spam checks, and duplicate controls reduce common forms of misuse.
Questions about security?
Contact us if you need more information about Valibrio's security controls, data access, participant submissions, billing, or AI processing.