Free security scan for AI-built apps

Know how secure your launch actually is.

LaunchGuard runs a passive AI security audit on your AI-built app. Paste your URL and watch it run, check by check. In under a minute: a Security Health Score, a grade for every category, and a plain-English report on what to fix first.

No login required. Passive only: no attacks, no contact with your users.
14 security categoriesOWASP-mapped findings
Now in operation
Swiss Made
--
READY
Security headersQUEUED
Cookies & sessionsQUEUED
TLS & certificateQUEUED
Exposed files & configQUEUED
JS secrets & source mapsQUEUED
DNS & email securityQUEUED
Frameworks & dependenciesQUEUED
Admin interfaces & APIsQUEUED
Public storageQUEUED
CORS & cross-origin policyQUEUED
Third-party scripts & supply chainQUEUED
API surface & documentationQUEUED
Subdomains & takeoverQUEUED
Brand & domain protectionQUEUED
01 / The problem

Anyone can build software now.
Not everyone can secure it.

You shipped fast on Replit, Bolt, Lovable, Cursor, or Vercel. Those tools handle a lot for you, but your app still holds credentials, payments, and personal data, and it has probably never had a security review. The risk is real, and most founders simply do not know what is wrong.

ReplitLovableBoltCursorVercel
02 / The stakes

Most apps go live with problems their founders never see.

of AI-built apps we scan carry a high or critical issue
average Security Health Score at launch
It is fixable.
once you can see it
03 / What LaunchGuard does

Know your risks. Fix what matters. Prove you're secure.

0Categories scanned
Know your risks
A passive scan across fourteen categories returns a Security Health Score and a plain-English finding for every issue it surfaces.
0Severity levels
Fix what matters
Every finding is prioritized and comes with a concrete fix, so your time goes to what actually moves the score.
0Score to verify
Prove you're secure
Clear the bar and earn LaunchGuard Verified, a public seal your users and investors recognize.
04 / Built for your stack

Built for how AI apps actually break.

Common in AI-built apps
CriticalExposed .env file with live API keysVercel
CriticalDatabase tables open to the publicSupabase
HighSource maps exposing your backend codeBolt
HighAdmin route reachable without a loginReplit
MediumNo Content-Security-Policy headerAll stacks

You shipped fast on tools that handle a lot for you. They also leave the same gaps, over and over. LaunchGuard is built around these apps and their recurring patterns, so the scan goes straight to where the problems tend to be.

ReplitBoltLovableCursorVercelSupabaseNext.js

If you built it this way, we have seen it before.

05 / Your score

Paste a URL.
See exactly where you stand.

0
GRADE D
Security Health Score
Security headers55
TLS & certs90
Cookies85
Exposed files20
JS secrets26
DNS & email60
Frameworks88
Admin panels50
Public storage82
CORS policy78
Supply chain64
API surface84
Subdomains91
Domain protection45

Fourteen categories, scored live in under a minute. Every finding comes with a clear fix. The first scan is free, and you do not need an account.

06 / How it works

From your first scan to a verified launch.

Each step is something you do and something you get back, and your Security Health Score climbs the whole way. Start free, no account needed.

Scan
Paste your URL. A passive audit runs in under a minute.
Report
The full report, free once you register with your email.
Fix
Do it yourself, or bring in a specialist.
Verify
Re-scan to confirm. Earn the seal.
Monitor
We keep watching and flag anything new.
07 / Managed remediation

You don't have to fix it alone.

When your report shows real risk, a LaunchGuard security specialist works through it with you, one finding at a time, until a closing Verify run confirms you pass. You approve every change, and nothing happens without you.

A named specialist
A real security professional assigned to your app, not a ticket queue.
Tracked finding by finding
Every issue in one workspace, from open to resolved, so you always know where things stand.
A closing Verify run
When the work is done, we re-scan to confirm, and you earn Verified.

Every Fix starts from a free scan.

Guided remediation0 of 4 resolved
Exposed .env file with live API keysCriticalTO DO
Database tables open to the publicCriticalTO DO
Admin route reachable without a loginHighTO DO
No Content-Security-Policy headerMediumTO DO
Ready for your Verify run
08 / The trust signal
LaunchGuard Verified seal
Swiss Made

Show people your app is secure.

Clear the bar, a score of 80 or above with no open critical or high findings, and you earn a public LaunchGuard Verified certificate. Drop the badge on your site with one snippet. It links to a trust page anyone can check, and it always reflects your live status, so it cannot show a claim that is not true.

61GRADE Dfrom 61
PASS 80
Clear 80, and a failing score becomes LaunchGuard Verified.
LaunchGuard
Verified
A · 92
Verified by LaunchGuard · Trusted Swiss security for AI-built software
Cert ID lg_8f3a2e9  /  Issued 14 Jun 2026  /  Valid 0 days
Fix Friday

Every Friday, one step safer.

Security is not a one-time scan. It is a habit. Every Friday, LaunchGuard reads the week across every AI-built app it watches, and every founder gets a nudge to fix one thing and re-scan. Small steps, every week, until you are Verified and staying that way.

The weekly ritual
Make AI security a weekly habit.

One insight from the whole community every Friday, and one personal step for your app. That is how a 52 becomes an 80.

BuildScanFixVerifyMonitorGet Verified
MissionMake AI security a weekly habit for every builder.
VisionA web where AI-built software is secure by default, one Friday at a time.
09 / After launch

We keep watching, so you don't have to.

Verified isn't a one-time checkmark. Continuous security monitoring keeps re-scanning your AI-built app every day and watching your certificate. The moment something material changes, you hear about it: what happened, and what to do.

Coming next: a public Verified directory, where being trusted helps people find you.

Monitoring
SEP 03
New finding on a re-scan: a public storage bucket appeared. Flagged the same day.notified
SEP 21
Certificate expiring in 14 days. Renew to keep your Verified badge live.notified
OCT 02
A fix is ready for your review. Your specialist finished the change.notified
10 / Questions

The short answers.

A passive audit across fourteen areas: security headers, TLS and certificates, DNS and email security, exposed files and config, public storage, cookies and sessions, JavaScript secrets and source maps, frameworks and dependencies, admin interfaces and APIs, CORS and cross-origin policy, third-party scripts and supply chain, exposed API surface and documentation, subdomain takeover exposure, and lookalike domain protection.

Yes. It's entirely passive: no attacks, no malicious traffic, no contact with your users. It only reads what your app already exposes publicly.

Under a minute, and no account is needed to run a scan and see your score.

Each of the fourteen categories is scored from the evidence the scan collects. Those combine into one Security Health Score, 0 to 100, with a letter grade from A to F.

Yes. Register with your email and the full report unlocks immediately: every finding, its business impact, how to fix it, and an OWASP mapping. There's no charge for the report.

When your report turns up real risk, a LaunchGuard security specialist works through it with you, one finding at a time, until a closing re-scan confirms you pass. It's a person doing the work with you, not a PDF of advice.

The price is sized to what your report actually finds, shown as an estimate up front. Your specialist confirms the exact price before you pay. It's a one-time fee per engagement, not a subscription.

No. The subscription is for everyone, whatever your score. It buys continuous monitoring and a live view of your climb toward the bar. The Verified badge is earned on top: it activates automatically the moment you pass (80 or above, no open critical or high findings). You subscribe to get watched and to climb; you earn the badge by passing.

$39 a month or $390 a year, with a 7-day free trial. That is the whole subscription: continuous monitoring, your climb toward the bar, and the Verified badge automatically once you pass.

LaunchGuard keeps re-scanning your app on a schedule and watching your certificate. When something changes that matters, you'll hear about it, in the app and by email.

Launch with confidence

Launch with confidence.

Run a free scan, fix what matters, and earn a trust seal people recognize. No account needed to start.

See your risks clearly.Fix what actually matters.Prove it with LaunchGuard Verified.

Passive only: no attacks, no contact with your users.

LaunchGuard
LaunchGuard

Know how secure your launch actually is.