Vraelis
How it worksPricingDevelopersResearchEnterprise
Sign inCheck your application

Enterprise and security

Govern production readiness across your organization.

Vraelis runs your AI-built apps like production before they ship. Enterprise teams govern who can connect apps and launch runs, verify organization domains, and keep audit-ready records of every run and decision. It is production infrastructure, not a dashboard.

Check your applicationView developer platform

What Vraelis protects

The decision, and everything around it.

Run workflows

Preflight runs go through a governed pipeline with an audit trail, not an open box anyone can trigger against anything.

Application ownership

Every connected app carries an explicit owner and an I own or authorized this confirmation before a run can touch it.

Organization access

Organizations sit above workspaces with roles, admins, and membership governance, so access maps to who should have it.

Client viewer access

Invite someone as a read-only client viewer, scoped to reports rather than settings, costs, or raw evidence. Sharing a report by public link, with no account, is not built yet.

SSO and domain-based access

OIDC single sign-on and verified-domain provisioning bind access to identities your organization already controls.

Billing and admin boundaries

Billing admins manage payment without owning data or members. Ownership transfer is a deliberate, guarded action.

Audit activity

Member, domain, SSO, billing-admin, ownership, and confirmation-round changes are recorded as a safe, reviewable trail.

Governance controls

Controls that exist today.

The access and identity controls a team can use to run preflight responsibly across an organization.

Organizations and workspacesProject-level accessRole-based access (admin / editor / viewer / client)Billing-admin separationOwnership-transfer controlsTokenized, expiring invitesVerified organization domainsDomain-based provisioning (governed)OIDC single sign-onPeriodic domain re-verificationRead-only audit activitySanitized audit export (CSV / JSON)

Auditability

A reviewable trail, without the secrets.

Workspace and organization activity are recorded as a read-only audit trail. Owners and admins review recent governance events in-app at Activity, and can export sanitized governance activity as CSV or JSON. Scheduled exports and retention controls are planned.

Vraelis records key governance events: organization changes, domain verification and re-verification, SSO provider changes, billing-admin changes, confirmation rounds, ownership transfers, and team-access updates. Audit events carry only safe fields: no secrets, no invite or DNS tokens, no token hashes, no Stripe identifiers, no API keys, no OIDC codes or SAML assertions, no certificate bodies, no full URLs, and no IP or device data.

Data handling

Honest about what we store and how.

No raw secrets in audit

Event metadata is whitelisted to safe fields. Emails, tokens, hashes, and Stripe ids are filtered out before anything is recorded or shown.

OIDC secrets encrypted

An organization's OIDC client secret is encrypted at rest (AES-256-GCM) and never returned to the client or logged.

DNS tokens hashed

Domain verification stores only the SHA-256 of the DNS TXT token. The raw token is shown once and never persisted.

Private run evidence

Screenshots and traces live in a private bucket. No public URL is ever produced, and reads go through short-lived, owner-authorized signed URLs.

You choose what a run can reach

Point runs at a preview or staging deployment and keep Stripe in test mode. Vraelis drives the app from the outside, so a run can touch whatever that environment touches.

Payments via Stripe

Card data is processed securely by Stripe. Vraelis never sees card numbers. Your billing overview stays in Vraelis.

We describe what Vraelis actually does. We do not claim formal certifications. If your organization needs specific compliance attestations, contact us to discuss requirements.

SSO and provisioning

Identity, governed and honest.

  • OIDC SSO is available

    Organizations can configure OIDC single sign-on for any verified domain. The id_token is validated (signature, issuer, audience, nonce) and the email domain must match the verified org domain.

  • SAML is in preview

    SAML configuration is a scaffold today. The SP metadata endpoint exists, but assertion sign-in is not enabled yet, and we will not pretend it is.

  • SCIM is not enabled yet

    Automated provisioning and deprovisioning (SCIM) is planned for larger organizations, not live today.

  • Domain provisioning is governed

    A verified-domain match maps a user into the organization at a safe role per your settings. It never grants workspace, project, billing, or API access by itself.

Plans

Recurring plans for standing access.

The front door is a free run. These recurring plans are for teams that verify continuously, priced by the run in monthly verifications. Some tiers are still rolling out, so talk to us and we will set you up.

Builder
$49/mo
Validate 10 launches / mo
For one product moving steadily toward launch.
Talk to us
Pro
$149/mo
Validate 40 launches / mo
For teams launching continuously across applications.
Talk to us
Scale
$399/mo
Validate 150 launches / mo
For agencies and platforms verifying at volume.
Talk to us
Enterprise: governed preflight at org scale

For organizations that need governance, SSO, and audit across many teams. Unlimited runs, Organization governance and audit export, OIDC SSO and verified domains, Client viewer access and billing admins.

Contact sales

For the avoidance of doubt

What Vraelis is not.

Not a testing dashboardNot a bug list you still have to triageNot a numeric quality scoreNot a code writer or auto-deployNot a guarantee, it is a readiness assessment

A decision you can defend, before you ship.

Check your applicationView developer platformContact us about enterprise SSO
Vraelis

Verifies software built with AI actually works. Name the outcome that must hold, and Vraelis checks the live result and keeps the evidence.

Product
How it worksLimitationsPricingEnterpriseCheck your application
Developers
Developer overviewCLI and CIResearchAPI & webhooks
Account
DashboardAccountBillingSign in
Legal
Enterprise & securityPrivacyTermsRefundsData rightsSubprocessorsTrademarkContact
© 2026 Vraelis. All rights reserved.Questions? Contact us