Security · For IT
Let teams move fast. Keep the keys.
Every app your team publishes is scanned and reviewed, then served in isolation. You set the rules once, and Vernissage applies them to every new version.
On every publish
Up to four steps for every version.
- 01
Scan
Malware, exposed secrets, unapproved domains and script sources. Known-vulnerable dependencies are reported when a lockfile is included.
- 02
Review
AI reviews the code and explains each finding it confirms.
- 03
Approve
Where your admins require it, an approver signs off before release.
- 04
Isolate
Served from its own address, and limited to the API domains your admins approve.
Scanning & review
Findings your builders can actually fix.
Each finding names the file and line where it can, the risk and, where there is one, the fix. Builders can fix and resubmit from the same AI conversation. Each resubmission counts as an update.
- Malware and exposed secrets block publishing
- Known-vulnerable dependencies are reported
- Automatic takedown if a live app is later found to hold malware, an exposed secret or a confirmed critical vulnerability
Admin controls
Decide who builds, and what goes public.
New members start as viewers, and an admin decides who can build. Turn off public apps, or require approval before a version is released.
- Only the builders you approve can publish
- Approval before release, when you want it
- Turning off public apps moves them back to Internal
Isolation & egress
Each app in its own room, doors you approve.
Every app has its own origin, separate from Vernissage itself, so browsers keep its storage apart from other apps'. Its code can fetch data only from the API domains your admins approved for that version.
- A separate origin for each app
- An approved-domain list your admins manage
- Scripts load only from sources that are approved
Identity & audit
Your identity provider. A clear record.
Sign in with email codes, or on a paid plan with your identity provider, starting with Microsoft Entra ID. Publishing, access changes and setting changes are recorded in an audit log on every plan, and an admin can revoke a member's sessions in one step.
- Single sign-on with your identity provider, on paid plans, starting with Microsoft Entra ID
- Audit history kept as long as your account exists
- Search the audit log and export it as CSV, on paid plans
For your security review
The answers, before you ask.
The details a review asks for first. Email us for the rest.
Email the security team- Single sign-on
- Your identity provider on paid plans, starting with Microsoft Entra ID
- Audit log
- Kept for the life of the account
- App isolation
- One origin per app
- Network access
- Approved domains, set per version
- Secrets
- High-confidence secrets, such as API keys and passwords, block publishing
- Default visibility
- Internal
Ready to let people build?
Join the waitlist, or email security@vernissageai.com with the questions on your checklist.