Security · For IT

Let teams move fast. Keep the keys.

Every app your team publishes is scanned and reviewed, then served in isolation. You set the rules once, and Vernissage applies them to every new version.

On every publish

Up to four steps for every version.

  1. 01

    Scan

    Malware, exposed secrets, unapproved domains and script sources. Known-vulnerable dependencies are reported when a lockfile is included.

  2. 02

    Review

    AI reviews the code and explains each finding it confirms.

  3. 03

    Approve

    Where your admins require it, an approver signs off before release.

  4. 04

    Isolate

    Served from its own address, and limited to the API domains your admins approve.

Scanning & review

Findings your builders can actually fix.

Each finding names the file and line where it can, the risk and, where there is one, the fix. Builders can fix and resubmit from the same AI conversation. Each resubmission counts as an update.

  • Malware and exposed secrets block publishing
  • Known-vulnerable dependencies are reported
  • Automatic takedown if a live app is later found to hold malware, an exposed secret or a confirmed critical vulnerability

Admin controls

Decide who builds, and what goes public.

New members start as viewers, and an admin decides who can build. Turn off public apps, or require approval before a version is released.

  • Only the builders you approve can publish
  • Approval before release, when you want it
  • Turning off public apps moves them back to Internal

Isolation & egress

Each app in its own room, doors you approve.

Every app has its own origin, separate from Vernissage itself, so browsers keep its storage apart from other apps'. Its code can fetch data only from the API domains your admins approved for that version.

  • A separate origin for each app
  • An approved-domain list your admins manage
  • Scripts load only from sources that are approved

Identity & audit

Your identity provider. A clear record.

Sign in with email codes, or on a paid plan with your identity provider, starting with Microsoft Entra ID. Publishing, access changes and setting changes are recorded in an audit log on every plan, and an admin can revoke a member's sessions in one step.

  • Single sign-on with your identity provider, on paid plans, starting with Microsoft Entra ID
  • Audit history kept as long as your account exists
  • Search the audit log and export it as CSV, on paid plans

For your security review

The answers, before you ask.

The details a review asks for first. Email us for the rest.

Email the security team
Single sign-on
Your identity provider on paid plans, starting with Microsoft Entra ID
Audit log
Kept for the life of the account
App isolation
One origin per app
Network access
Approved domains, set per version
Secrets
High-confidence secrets, such as API keys and passwords, block publishing
Default visibility
Internal

Ready to let people build?

Join the waitlist, or email security@vernissageai.com with the questions on your checklist.

Join the waitlist