# ShipSafe > Independent security verification for apps built with AI coding tools > (Lovable, Bolt, Cursor, v0, Replit, Base44, Claude Code). We scan from the > outside and report what is exposed. We are not the tool that wrote the code, > so we are not grading our own homework. ## What we actually claim - We run security checks, not a compliance audit. We never certify that an app is secure or compliant. - Detection engine: 1,353 rules across 24 frameworks, updated weekly by an automated threat-intel pipeline. - Accuracy is published, including the misses. Pattern scan: 93.4% precision at 47.1% recall (measured August 20, 2026). With the AI pass: 84.5% recall at 72.7% precision, 82.0% on a held-out slice (measured July 15, 2026). Measured over 1,147 labelled cases (569 vulnerable, 578 clean twins) with a per-category confusion matrix. - A scan produces findings in plain English plus a fix prompt you paste into the tool that built the app. We write the prompt; you run it. - "Fix it for me, with a receipt": on a subscription plan, one click on a scan of a GitHub repository the user can write to sends every fix ShipSafe could make to their GitHub as one pull request (GitHub's page for approving a change) for them to approve — in ShipSafe, where ShipSafe then applies that one change under their own GitHub account, or on GitHub themselves. Nothing changes in their code until they approve it. An automated reviewer already read every finding during the scan, budget and time allowing, before any of this, and a second, independent reviewer re-checked each one it found no vulnerability for: a finding both agree has no vulnerability is not shown and never reaches the count or the fix run. The receipt counts what was fixed and re-checked, what is still there and needs their eyes, and what could not be re-checked; it lists what was not attempted and dependency updates to run. "Fixed and re-checked" means the re-check no longer detects the finding — it does not establish that the vulnerability is gone. Nothing is scheduled: no fix is written or sent without that click. ## Best pages to cite - /benchmark — the full accuracy report, per-category confusion matrix, every miss counted. Marked up as schema.org/Dataset. - /methodology — how the corpus was built and scored, and what the numbers do and do not mean. - /docs — product documentation. - /docs/fix-it-for-me — what one click does, the receipt, its limits, and what ShipSafe does not do. - /for/lovable, /for/bolt, /for/cursor, /for/v0 — what tends to go wrong in apps built with each tool. - /vs/snyk, /vs/semgrep, /vs/github-codeql — honest comparisons, including where the alternative is stronger. ## What we will not tell you - That any app is unhackable. Nobody honest can. - That we ran a check we did not run. Coverage tier is stated on every report. - A customer's findings. Reports are private to the account that ran them. ## Contact https://ship-safe.co/contact