Skip to main content

we automatically scan and fix all of your projects weekly.

Tuned for the code your builder writes

1,347 checks·updated weekly

LovableCursorBolt.newReplitv0Claude CodeWindsurfChatGPTCopilotDevin

Five steps. You do two.

Both of yours are one click. We handle the middle.

Pricing

You’re not buying scans. You’re buying not having to think about it.

We don’t host your code. We don’t keep your ideas. We don’t train anything on your creativity. We do the work — and then we do it again next week.

Solo

$19/mo

  • 4 AI deep scans a month
  • Up to 1 project watched at once
  • No automatic re-scans
Get Solo
Most people

Shield

$29/mo

  • 10 AI deep scans a month
  • Up to 2 projects watched at once
  • Re-scanned every two weeks
  • A Verified badge, plus a public proof page
Get Shield

Growth

$49/mo

  • 20 AI deep scans a month
  • Up to 4 projects watched at once
  • Re-scanned every week
  • A Verified badge, plus a public proof page
Get Growth

Every plan reaches the same people. Shield gets answered first.

Every plan is the same product. They differ in four things: how many deep scans you get, how many projects we watch, how often we re-scan them, and how quickly we answer you. Every plan includes:

  • AI deep scans that read your auth, access control and database rules
  • Findings in plain English, with the file and the line
  • AI Fix Prompts for Cursor, Claude Code, Lovable and Bolt
  • The fix written for you after a re-scan — you approve before anything merges
  • Email alerts and scan diffs when you push to your default branch — once a day at most
  • CLI, MCP and GitHub Actions, to scan as you build

Prices include VAT and sales tax where they apply — what you see is what you pay. Buying for a company? Add your VAT number at checkout for a business invoice.

Just want one look? — $9, once

One deep scan and every finding it turns up. No plan, nothing renews, and we do not watch the project afterwards.

See the one-time audit
The honest version

What “we fix it” actually means.

Not magic, and we’d rather tell you exactly how it works than let you imagine something we don’t do.

We write the fix. You press yes.

For most things we find, we write the exact change and show you what it does in one sentence. You paste it in, and for anything visible from the internet — headers, CORS, cookie flags — we check it again from outside to prove it actually closed. Prefer to do it yourself? Copy it straight into Cursor.

The rules that apply where you are

Selling to people in Europe means one set of rules. Taking card payments means another. Tell us where you are and we show you which of them a finding actually touches — instead of handing you a list of regulations you’ll never need.

Why once is never enough

Your app doesn’t change, but the world does. New ways in get published every week, and something that was fine on Monday can be a problem by Friday. That’s why the badge expires — so when it’s showing, it means recently, not once, a while ago.

What actually happens when you press the button.

No mystery box. Here’s the whole thing, timed.

  1. 00:00

    You paste a link.

  2. 00:12

    We map what you built.

  3. 00:47

    First finding appears.

  4. 01:30

    Fixes get written.

  5. 02:04

    Done, and the copy is dropped.

  6. +7d

    We look again. Without being asked, on Growth and Shield.

Typical timings on a small repo, not a guarantee — a large codebase takes longer.

Why people pick us over the alternatives.

All four of these are real options. Here’s where each one actually lands.

Ask the AI that built it

Free

  • No: Only sees what you paste
  • No: Can’t test your live site
  • No: Tends to agree with you
  • No: Grading its own homework

A proper security tool

$300+/mo

  • Yes: Genuinely thorough
  • No: Written for security teams
  • No: You’d have to learn it first
  • No: Finds things, fixes nothing

Hire someone

$3k+/audit

  • Yes: A real human expert
  • No: Weeks of waiting
  • No: One snapshot, then it ages
  • No: Out of reach for most people

ShipSafe

$9 once

  • Yes: Independent of whatever built it
  • Yes: Written so you can act today
  • Yes: We write the fix, not just the finding
  • Yes: Kept current on a plan, not a one-off

There’s a person on the other end.

Not a chatbot with a human name. If something’s gone wrong at 2am and you don’t know what you’re looking at, you send us the screenshot and someone who does this every day reads it with you. That’s included at every price, and it always will be.

We’d rather you asked us something obvious than sat there worrying about it.

Every plan
Talks to a real person
Weekly
Automatic re-checks on Growth — every two weeks on Shield
11 lines
Of code kept per finding, secrets redacted

And here’s what we never do.

We don’t keep your codebase.

We read it, check it, and drop the copy we were working from. What stays is the finding itself — the file, the line, and a few lines around it, so you can see what we meant. Delete your account and that goes too.

We don’t train on what you’re building.

Your idea isn’t training data — not for us, and not for the AI we call. What we do keep is your own calls: mark a finding a false positive and the assistant remembers, for your account only, so it doesn’t argue the same point twice. We also look at whether that rule was wrong — the rule, the file it fired on, and why you disagreed. Not your project.

We don’t promise you’re unhackable.

Nobody honest can. We tell you what we checked, what we found, and when — and the badge says so plainly.

We don’t make you learn our language.

If a result needs a glossary, we wrote it badly and we’ll fix it.

Ready to stop thinking about it?

Load your app. We read it, and we write the fix for you to paste.

Better you find it than someone else.

Free to start. No card.

Load my app — free
No card·Nothing to install·If we find nothing, we say so

See what the plans include