Scan Types

What LaunchSafe scans today: free public repository grades and Supabase settings checks today, and code scans of GitHub repositories when they open. Live-app testing is not open yet.

Edit on GitHub

What runs today

ScanWhat it looks atCost
Code scan (when scans open)A GitHub repository: the code, its dependencies, and secrets committed to itScan credits, by quote
Retest (when scans open)One finding, to see whether it is fixedFree within an allowance. See fix pull requests and retests
Supabase settings checkA connected Supabase project's security settingsFree. See Supabase
Public gradeA public GitHub repository, for anyoneFree. See the public grade

When code scans open, a scan runs at one of three depths: quick (up to 60 minutes), standard (up to 6 hours) or deep (up to 24 hours). The quote shows the cost before you start.

What a scan tells you

Every scan records what it covered: code analysis, dependencies, committed secrets. A scan that did not cover something, or stopped early, says so. LaunchSafe never reports lost coverage as "nothing found".

A finding is never closed just because a later scan did not see it. See findings.

Not available yet

  • Testing a live URL (black-box, or combined with code) is not open yet. You can prove you control a domain and save a target's scope settings now. See domain verification.
  • Scheduled scans are not available.
  • ZIP upload is not available.
  • GitLab and Bitbucket scans. You can connect them, but scans cannot fetch their code yet.

On this page