webium.ai
Security

Security

Webium's security principles, customer responsibilities and responsible vulnerability-reporting process.

Effective: September 3, 2026

Security approach. Webium uses third-party cloud infrastructure and applies security controls appropriate to an AI-assisted application-building and hosting service. This page is a security overview, not a certification or guarantee that every generated customer application satisfies a particular compliance standard.

Security principles

Customer responsibilities

Security is shared. Customers should use strong unique passwords, protect account access, review who can access projects, rotate exposed credentials, test generated applications, keep external integrations secure and avoid storing restricted data unless Webium has expressly approved the use.

Generated-code security

AI-generated source code can contain vulnerabilities. Webium may use automated and manual safeguards, but customers should not treat generated code as independently audited merely because Webium produced it. Applications with high-risk data or consequential functions may require specialized security review.

Responsible vulnerability reporting

If you believe you found a security vulnerability in Webium itself, email support@webium.ai with a clear description, affected URL/feature and steps needed to reproduce the issue.

Please avoid accessing data that does not belong to you, disrupting the Service, using destructive testing, publicly disclosing an unremediated vulnerability, or conducting social engineering. This page does not create a paid bug-bounty program or authorize testing outside your own account except as expressly agreed by Webium.

Incident communications

If Webium confirms a security incident requiring customer or regulatory notification, Webium will provide notices as required by applicable law and contractual obligations.