Where do our tools actually run?
In your own cloud account. A deploy goes to your Vercel, Netlify or Cloudflare, using a token your organisation added and Vibtra sealed. Vibtra’s own control plane is built for Sydney (ap-southeast-2) and is not deployed yet; your tool would never run on it in any case.
What does Vibtra itself see?
What it was given: the records of what was deployed, the credentials you sealed, and the sign-in decisions it made. It is not in your tool’s data path. The one hop it sits on is the sign-in gate. When the console inspects a connected system it reads object names, field names and field types, never a row of data.
Who can open a tool once it is deployed?
Whoever its audience says: the whole organisation, a named group, or named people. You change it in the console and it takes effect at the next sign-in, with no redeploy, and nothing about a person is ever compiled into the app. Someone left out can ask for access, and the approval runs the same rule the form does.
What happens to a credential?
It is sealed in your organisation’s vault and resolved into a deploy’s environment at the moment that deploy needs it, after the audience is checked. You can point a connection at an item in your own 1Password instead, which is read at each use and stored nowhere. On Postgres and MySQL, Vibtra can hand the whole problem to OpenBao, which mints a database user per use with an expiry, after which we hold no password at all.
Does it replace our cloud accounts or our identity provider?
Neither. Deploys land in the cloud accounts you already have, and sign-in is Google or an OIDC provider you register, Okta and Microsoft Entra ID among them. Vibtra sits between the two and keeps the record.
What happens when someone leaves?
Every tool has an owner, and an owner can be changed, which writes its own record naming who handed it to whom. A tool nobody needs any more is archived, which closes its sign-in gate. Neither act deletes any history.
Can we run Vibtra ourselves?
Not today, and we would rather say so than imply otherwise. There is no self-hosted image at launch. Residency is answered by hosting in Sydney (ap-southeast-2), which is what the control plane is built for; if running it inside your own estate is a requirement, that is a conversation to have with us rather than a download.