> ## Documentation Index
> Fetch the complete documentation index at: https://docs.vibely.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# Vibely for Enterprise

> Run Vibely across an organization with centralized identity, workspace governance, audit logs, private packages, and terms set on a signed Order.

Vibely Enterprise gives organizations a governed workspace for building apps with AI: centralized sign-in and provisioning, workspace-wide publishing and sharing controls, audit logs, private npm packages with build secrets, and a commercial relationship defined on a signed Order rather than a self-serve checkout.

<Frame>
  <img src="https://cdn.vibely.sh/doc/v1/get-started-enterprise.webp" alt="Vibely for Enterprise" width="1200" height="675" />
</Frame>

Enterprise is sales-led. There is no checkout for it; your seats, credit volume, and terms are set on an Order, and your workspace is provisioned onto the Enterprise plan when the Order is signed. Features marked **Business and Enterprise** are also on the self-serve Business plan. Features marked **Enterprise only** need the Enterprise plan.

<Card title="Talk to our sales team" icon="arrow-right" horizontal href="https://vibely.sh/contact-sales">
  Tell us about your identity provider, security requirements, and use case, and we'll put together an Order.
</Card>

## At a glance

| Area | Covered by |
| :- | :- |
| **Identity** | SSO (SAML or OIDC) with domain verification, Require SSO, SCIM provisioning, workspace groups, roles |
| **Governance** | Invitation restrictions, allowed email domains, project transfer controls, required editor role, external collaborator limits, code download controls, required two-factor authentication |
| **Publishing** | Default website access, who can publish externally, preview link sharing, publish gates for critical issues and personal data |
| **Security** | Per-project scans, Security center with scheduled scans, sensitive data scanning |
| **Auditability** | Audit logs with filters and CSV export |
| **Code and packages** | GitHub sync, code download, managed npm registry, build secrets |
| **Data** | No model training on your data; product-improvement collection off by default; published DPA and subprocessor list |
| **Commercial** | Seats, credit volume, invoicing, support contacts, and uptime commitment set on a signed Order |

## Who Enterprise is for

Enterprise workspaces suit organizations that need to:

* Control who can invite people, publish externally, share previews, and move projects out of the workspace
* Keep a searchable, exportable record of membership, project, and security changes
* Share private npm packages across every project, with registry credentials that never reach the running app
* Buy on invoice, with terms negotiated on an Order instead of accepted at checkout

## What Enterprise adds beyond Business

Business already includes SSO with Require SSO and session duration, SCIM provisioning, groups, the Security center and Workspace Insights, audit logs with CSV export, every control in [Privacy & security](/features/workspace/privacy-security), restricted projects, the workspace template library, design systems, branded workspace URLs, and workspace connector controls. Enterprise adds:

* **Build and packages**: [Build secrets](/features/build/build-secrets) and the [Managed registry](/features/build/managed-registry).
* **Commercial terms**: the terms listed under [Commercial terms](#commercial-terms).

## Identity and access

Centralize how your team signs in and gets access to Vibely.

<CardGroup cols={2}>
  <Card title="Single sign-on" icon="shield-keyhole" href="/features/workspace/sso">
    **Business and Enterprise.** Connect any SAML or OIDC identity provider after verifying your email domain. Make SSO optional or turn on **Require SSO**, which signs out any member (except the owner) who didn't sign in through your identity provider, and set a session duration of 24 hours, 48 hours, or 7 days.
  </Card>

  <Card title="SCIM provisioning" icon="users-gear" href="/features/workspace/scim">
    **Business and Enterprise.** Create and deactivate members from your identity provider with a SCIM bearer token you can rotate or revoke, and set the role SCIM users get.
  </Card>

  <Card title="Workspace groups" icon="users" href="/features/workspace/groups">
    **Business and Enterprise.** Group members, let group Admins manage their own group's Members, and control who can open a published app by group.
  </Card>

  <Card title="Roles and permissions" icon="user-shield" href="/features/collaboration/overview">
    Owner, Admin, Editor, and Viewer roles, each checked server-side on every request.
  </Card>

  <Card title="Require two-factor authentication" icon="lock" href="/features/workspace/privacy-security">
    **Business and Enterprise.** Publishing and changing build secrets ask for a two-factor code. Members set up an authenticator app in **Settings → Account**.
  </Card>

  <Card title="Restrict workspace invitations" icon="ban" href="/features/workspace/privacy-security">
    **Business and Enterprise.** Only admins and owners can invite members, and invitations outside your allowed email domains are blocked.
  </Card>
</CardGroup>

<Note>
  SSO and SCIM are configured in **Settings → Identity**. Only workspace owners and admins can change it.
</Note>

## Workspace governance and data protection

Set workspace-wide policies once and apply them to every project. These controls live in **Settings → Privacy & security**. See [Privacy & security](/features/workspace/privacy-security).

<CardGroup cols={2}>
  <Card title="Project transfers" icon="arrow-right-from-bracket" href="/features/workspace/privacy-security">
    **Business and Enterprise.** Decide whether members who own a project can transfer or remix it into another workspace, including a personal one.
  </Card>

  <Card title="Require workspace editor role" icon="user-lock" href="/features/workspace/privacy-security">
    **Business and Enterprise.** Members with the viewer role can open projects but never change them, even projects they own.
  </Card>

  <Card title="External project collaborators" icon="user-plus" href="/features/workspace/privacy-security">
    **Business and Enterprise.** Cap the role people outside the workspace can hold on a project, or turn external collaborators off.
  </Card>

  <Card title="Sensitive data scanning" icon="user-magnifying-glass" href="/features/workspace/privacy-security">
    **Business and Enterprise.** Scan project source for personal data and raise findings in the Security center.
  </Card>

  <Card title="Training data" icon="database" href="/features/workspace/privacy-security">
    **All plans.** Vibely never uses your code, prompts, or project data to train models. **Allow data collection for training** is off by default.
  </Card>

  <Card title="Abandoned projects" icon="clock" href="/features/workspace/privacy-security">
    **Business and Enterprise.** Flag published projects that go a set period without edits, messages, or deploys in Workspace Insights. Nothing is deleted automatically.
  </Card>
</CardGroup>

## Publishing and sharing controls

Govern how projects are shared inside the workspace and how published apps reach the outside world.

<CardGroup cols={2}>
  <Card title="Default website access" icon="lock" href="/features/deploy/publish">
    **Business and Enterprise.** Set whether new publishes are open to anyone, to workspace members, or private by default.
  </Card>

  <Card title="Who can publish externally" icon="user-shield" href="/features/workspace/privacy-security">
    **Business and Enterprise.** Limit public publishing to editors and above, or to owners only.
  </Card>

  <Card title="Preview link sharing" icon="eye-slash" href="/features/workspace/privacy-security">
    **Business and Enterprise.** Control whether members can share preview links.
  </Card>

  <Card title="Code downloads" icon="file-zipper" href="/features/workspace/privacy-security">
    **Business and Enterprise.** When off, nobody in the workspace can download project source as a zip or a single file.
  </Card>

  <Card title="Publish gates" icon="shield-exclamation" href="/features/security/project-view">
    Block publishing when a scan reports critical issues, and require a basic security scan before a project's first publish.
  </Card>

  <Card title="Branded workspace URLs" icon="globe" href="/features/deploy/branded-urls">
    **Business and Enterprise.** Publish every app under your workspace's own address pattern.
  </Card>
</CardGroup>

## Audit and monitoring

Keep a record of activity across the workspace, and one place to check security posture.

<CardGroup cols={2}>
  <Card title="Audit logs" icon="clipboard-list" href="/features/workspace/security-center">
    **Business and Enterprise.** Every membership, project, and security change, with actor, IP address, and user agent. Filter by actor, action, and date, and export to CSV (up to 10,000 rows per export; a larger export tells you it was truncated). Owners and admins only.
  </Card>

  <Card title="Security center" icon="shield" href="/features/workspace/security-center">
    **Business and Enterprise.** Workspace security posture, SSO and SCIM status, invitation restrictions, recent audit activity, and scheduled scans across all projects or published projects only.
  </Card>

  <Card title="Project security view" icon="bug" href="/features/security/project-view">
    **All plans.** Per-project scan results, with findings you can fix from chat.
  </Card>

  <Card title="Workspace insights" icon="chart-line" href="/features/workspace/insights">
    **Business and Enterprise.** One row per active project, ranked by how urgently it needs a security review.
  </Card>
</CardGroup>

<Note>
  Open audit logs from **Settings → Security → Audit logs**.
</Note>

## Code, packages, and hosting

Keep code portable and install private packages safely.

<CardGroup cols={2}>
  <Card title="Build secrets" icon="key" href="/features/build/build-secrets">
    **Enterprise only.** Encrypted workspace values injected only while a project installs and builds, such as an npm token. Values can't be read back by anyone. **Settings → Build secrets**.
  </Card>

  <Card title="Managed registry" icon="box" href="/features/build/managed-registry">
    **Enterprise only.** Publish scoped npm packages to a private registry inside your workspace and install them in any workspace project. **Settings → Managed registry**.
  </Card>

  <Card title="GitHub sync" icon="github" href="/integrations/github">
    Sync projects to repositories you choose through the Vibely GitHub App.
  </Card>

  <Card title="Host outside Vibely" icon="cloud-arrow-up" href="/features/deploy/external-hosting">
    Deploy the code to infrastructure you operate when policy requires it.
  </Card>
</CardGroup>

## Where your data lives

* Application servers and project sandboxes run in the United States (AWS us-east-1).
* Vibely's own database, authentication, and file storage run on Supabase in Singapore.
* Your app's data lives in your own Supabase project, in the region you choose when you connect it. See [Supabase](/integrations/supabase).

Vibely doesn't operate an EU or India hosting region today. The current subprocessor list is at [vibely.sh/subprocessors](https://vibely.sh/subprocessors).

## Compliance

Vibely publishes its position on the [Security page](https://vibely.sh/security) and the [Trust page](https://vibely.sh/trust):

* **GDPR**: an Article 28 [Data Processing Agreement](https://vibely.sh/dpa), including the EU SCCs and the UK Addendum, that applies without signature.
* **SOC 2 and ISO 27001**: Vibely holds neither, and no audit or certification is under way. We answer security questionnaires in writing instead.
* [Privacy Policy](https://vibely.sh/privacy-policy) and [Subprocessors](https://vibely.sh/subprocessors).

## Commercial terms

An Enterprise Order sets:

* Seats and the per-seat price
* Credit volume and the overage rate
* Annual invoicing in USD, net 30, with no card on file
* Named support contacts with target first-response times
* A security questionnaire answered once a year, within 30 days
* A negotiated uptime commitment and liability cap

The written terms are at [vibely.sh/enterprise-terms](https://vibely.sh/enterprise-terms).

## Get started

<Card title="Talk to our sales team" icon="arrow-right" horizontal href="https://vibely.sh/contact-sales">
  Tell us about your identity provider, security requirements, and use case. You can also email [sales@vibely.sh](mailto:sales@vibely.sh).
</Card>

## FAQ

<AccordionGroup>
  <Accordion title="What's the difference between Business and Enterprise?">
    Business is the self-serve top tier. It includes SSO, SCIM provisioning, groups, the Security center, audit logs with CSV export, the governance, publishing, and data-protection controls in Privacy & security, restricted projects, the workspace template library, branded workspace URLs, and workspace connector controls.

    Enterprise is a contract plan. It adds build secrets, the managed registry, and the commercial terms set on your Order.
  </Accordion>

  <Accordion title="How do we move from Business to Enterprise?">
    Contact sales. Once the Order is signed, your existing workspace is moved onto the Enterprise plan. Your members and projects stay where they are.
  </Accordion>

  <Accordion title="Does Vibely support our identity provider?">
    Vibely supports any SAML or OIDC identity provider, and SCIM provisioning from any provider that supports SCIM 2.0. Verify your email domain first, then connect your provider from the Identity settings page.
  </Accordion>

  <Accordion title="Is our data used to train AI models?">
    No. Vibely doesn't use your prompts, code, or project data to train models, on any plan. The optional product-improvement setting, **Allow data collection for training**, is off by default. The [Security page](https://vibely.sh/security) lists how each model provider handles API traffic.
  </Accordion>

  <Accordion title="Can editors move projects outside our organization?">
    Not if you turn **Project transfers** off. On Business and Enterprise, this setting decides whether members who own a project can transfer or remix it into another workspace, including a personal one.
  </Accordion>

  <Accordion title="Is Vibely HIPAA-compliant?">
    No. Vibely doesn't sign Business Associate Agreements. Don't use Vibely to process protected health information.
  </Accordion>

  <Accordion title="How does billing work for Enterprise?">
    Seats, credit volume, and the overage rate are set on your Order. Vibely invoices annually in USD, net 30, with no card on file.
  </Accordion>
</AccordionGroup>


## Related topics

- [Welcome to Vibely](/introduction/welcome.md)
- [Build secrets](/features/build/build-secrets.md)
- [Managed registry](/features/build/managed-registry.md)
- [FAQ](/faq.md)
- [Vibely workspace](/features/workspace/overview.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.