VibeDefend is an agent-time security layer for AI coding tools. One npm install wires Claude Code, Cursor, Windsurf, GitHub Copilot, and OpenAI Codex to CybeDefend so business rules and security checks run while the agent writes code—not after the pull request. Free plan available ($0, 10 static scans and 50 AI credits); paid Developer starts at $21/month (USD). Built for developers and AppSec teams who already ship with coding agents.
This page is a compiled listing from CybeDefend’s own product, pricing, and docs pages, checked on 2026-09-29. It is not a hands-on product review. VibeDefend launched on the MPAT board as a morning slot for editors covering AI coding security.
VibeDefend sits between your coding agent and risky edits. Instead of waiting for a CI scanner after commit, it injects relevant business and security rules into the agent’s context before edits, scans the live diff, and can hard-block destructive shell or SQL actions before they run. The npm package is free to install; the CybeDefend platform behind it is what free and paid plans unlock.
What VibeDefend does
Checked on the vendor product page and docs on 2026-09-29. Install with npx -y @cybedefend/vibedefend@latest install (Node 18.17+). The installer detects supported agents, lets you pick EU or US region, and signs you into the matching CybeDefend tenant.
On supported agents, VibeDefend adds an MCP server plus hooks. Before Edit / Write / MultiEdit, it injects business rules mined from your codebase and security rules aligned with frameworks the vendor lists (including OWASP, SOC 2, GDPR, and ISO 27001). On tool calls, Action Guards evaluate the call against policy and can deny destructive commands such as unrestricted rm -rf, schema drops, or raw secret reads. At session start it loads doctrine and a proposals inbox; at session end (and on PreCompact for long sessions on some agents) it can run a gap analysis that proposes undocumented rules you relied on.
Link each repo with a .cybedefend/config.json containing your project UUID from the CybeDefend dashboard (or set CYBEDEFEND_PROJECT_ID). The platform side also exposes reachability-aware SAST, SCA, IaC, secret detection, and related scanners; VibeDefend is the agent-time front door to that stack. Agent support matrix (from vendor docs): Claude Code, Cursor, OpenAI Codex, Windsurf, and VS Code Copilot get first-class install; other MCP clients can use bring-your-own MCP config. Capability depth varies by agent—for example Windsurf write hooks are stronger than non-write tool blocks, and Copilot Action Guards are not yet fully wired per the docs matrix.
Who it is for / who should skip it
Good fit if: you already use Claude Code, Cursor, Codex, Windsurf, or Copilot daily; you care about business-logic bugs (tenant scoping, refund ceilings, missing auth middleware) as much as CVE lists; and you want a free starting point with published paid tiers rather than a pure sales quote.
Skip it if: you do not use AI coding agents; you only need post-commit CI scanning and already have a scanner you trust; you cannot send analysis traffic to CybeDefend’s EU (Paris) or US (Iowa) regions; or you need hard Action Guards on an agent the vendor still marks as unsupported for that feature. Teams that want Slack/Teams IT ticket agents should look elsewhere—this product is for code generation security, not ITSM.
Plans and prices
VibeDefend itself is included on every CybeDefend plan, including Free. The table below is CybeDefend platform pricing in USD, as published on the vendor pricing page and FAQ (checked 2026-09-29). Monthly list prices follow the FAQ and schema offers ($21 / $249 / $699); yearly totals match the pricing page ($228 / $2,748 / $7,680). Card UI may show the yearly-equivalent monthly rate when the Annual toggle is selected.
| Plan | Price (USD) | What you get | Where free / limits stop |
|---|---|---|---|
| Free | $0 (no card, no time limit) | 10 static scans; 50 AI credits; access to the whole platform; VibeDefend install included | Static scans capped at 10; AI credits at 50 (AutoFix / BLSA). No unlimited static scans. |
| Developer | $21/month, or $228/year | 3 repositories, 1 seat, 100 AI credits/month; unlimited static scans (SAST, SCA, IaC, secrets); VibeDefend, IDE plugins, AutoFix; GitHub & GitLab; email support | Repo and seat ceilings; 100 AI credits/month for credit-consuming features |
| Team | $249/month, or $2,748/year | 10 repos / 5 seats (add-ons: +$12/repo, +$24/seat per month, up to 20 repos / 10 seats); 1,500 AI credits/month; containers, CI/CD, REST API, Slack, Jira, Linear, RBAC, GRC/SIEM export | Credit and seat/repo caps without add-ons |
| Scale | $699/month, or $7,680/year | 25–50 repos / 15–25 seats with same add-on rates; 5,000 AI credits/month; AI-BOM, SBOM, policies, OWASP/CWE reports (90-day retention), BLSA early access, dedicated Slack, onboarding workshop | Shared infrastructure; no Enterprise SLA / SSO package |
| Enterprise | Custom quote | Unlimited repos, seats, and AI credits; SSO/SAML; private deployment options; 99.5% uptime SLA; account manager; 24/7 priority support | Sales-led; confirm scope in the quote |
USD, checked 2026-09-29, from https://www.cybedefend.com/en/pricing and the VibeDefend FAQ on the product page. AI credits power Cybe AutoFix and BLSA; static SAST/SCA/IaC/secret scans do not consume credits on paid plans. Startup programme: up to 6 months free (incubated, pre-funding) or 3 months free (Seed to Series A) on a chosen paid plan after application.
How it compares to tools already on MPAT
- Tines — secure workflow automation for agents and integrations. MPAT records a Free edition at $0 (capped at 3 live workflows) with paid editions via sales. Use Tines when the job is orchestrating security workflows across SaaS; use VibeDefend when the job is stopping bad code and dangerous agent actions inside the IDE/CLI agent loop.
- n8n — visual workflow automation with AI-agent nodes; self-hosted Community Edition free forever, Cloud Starter from 20€/month billed annually (per MPAT’s n8n page). Strong for gluing APIs and agents together; not an agent-time SAST/guardrail product.
- NiroHelp — WordPress help desk with optional AI answers from your docs (free plugin; paid AI from $9.99/month). Same “AI + free tier” pattern on MPAT, but a completely different job (customer support on WordPress vs coding-agent security).
Browse more on the MPAT homepage board and developer tools when that category filter matches your search.
Billing and data details worth checking
Billing mixes seat, repository, and AI-credit dimensions. Static scans are unlimited on paid plans; AutoFix patches and BLSA business-logic analyses spend AI credits. Add-ons for Team/Scale are billed monthly even if the base plan is annual. Data residency is chosen at signup: EU (eu.cybedefend.com) or US (us.cybedefend.com). The vendor states the local guard decides on-device for blocks, analysis stays in-region on their models, and code is not used to train third-party models—verify current claims on their Trust Center before a compliance review.
Codex users should note a docs gotcha: Codex 0.131+ requires approving CybeDefend hooks in the /hooks panel before they become active. Without that step, hooks show installed but inactive.
Is VibeDefend free?
Yes to install and to start. The npm installer is free. CybeDefend Free includes VibeDefend plus 10 static scans and 50 AI credits with no card and no time limit. Paid plans unlock unlimited static scans, higher AI credits, multi-repo seats, and team features.
How much does VibeDefend / CybeDefend cost?
Checked 2026-09-29: Free $0; Developer $21/month or $228/year; Team $249/month or $2,748/year; Scale $699/month or $7,680/year; Enterprise custom. The vendor FAQ phrases Developer as “€19 or $21 a month.” Confirm live figures on the pricing URL before you buy.
What is VibeDefend used for?
Teams use it so AI coding agents write against company business rules, get diff findings before the PR exists, and cannot run certain destructive commands. It is agent-time AppSec and policy enforcement, not a general chatbot.
Which coding agents does it support?
First-class install for Claude Code, Cursor, OpenAI Codex, Windsurf, and VS Code Copilot. Other MCP-capable clients (Gemini CLI, Cline, Continue, Zed, and similar) can use manual MCP setup. Feature depth (Action Guards, session hooks) differs by agent—read the vendor support matrix in the docs.
Does my code leave my machine?
Per vendor FAQ: analysis traffic goes to the region you pick (Paris EU or Iowa US) on their infrastructure; the guard can decide locally for blocks; telemetry for the guard is described as metadata-only; findings stay in-region; training on your code is disclaimed. Treat that as vendor policy text, not an audit result, and re-check before regulated deployments.
Sources
- https://www.cybedefend.com/en/vibedefend — product page (checked 2026-09-29)
- https://www.cybedefend.com/en/pricing — plans and limits
- https://www.cybedefend.com/en/blog/vibedefend-just-shipped — launch post
- https://docs.cybedefend.com/latest/agent-ai-integration/vibedefend — install, hooks, agent matrix



