Introduction

LaunchSafe finds security problems in your code, shows the evidence, opens fix pull requests for you to approve, and proves the fix with a retest.

Edit on GitHub

LaunchSafe is security testing for software teams. When repository scans open, you connect a GitHub repository, LaunchSafe's AI agents look for vulnerabilities in the code, and you get findings with evidence, fix pull requests you approve, and reports a customer or auditor can check.

What you can do today

  • Grade a public repository for free. No account needed. See the public grade.
  • Scan a repository (when scans open). Link a GitHub repository to a project, see the price in credits first, and start a code scan. A scan looks at the code, its dependencies and secrets committed to it. See scan types.
  • Read findings with evidence. Each finding says what is wrong, where, how it was proven, and how to fix it. See findings.
  • Fix with a pull request you approve. LaunchSafe writes the fix and shows it to you. Nothing is pushed to GitHub until you approve. See fix pull requests and retests.
  • Check the fix. A retest decides whether a finding is fixed. Only a retest closes a finding.
  • Issue signed reports. Anyone holding a report file can check it on a public page without an account. See signed reports.
  • Connect Supabase. A read-only check turns your Supabase project's security settings into findings. See Supabase.
  • Work where your team works. Slack, Jira and Linear are supported. See integrations.

How a scan will work

This is how repository scans work when they open for your organization.

Link your code

Connect GitHub and link a repository to a project.

Get a quote

Choose a depth and see the cost in credits before anything starts.

Scan

LaunchSafe's engine analyzes the code. You can cancel a running scan.

Review and fix

Triage findings, ask for a fix, approve the pull request, merge it.

Retest and report

A retest confirms the fix. Then issue a report if you need one.

What LaunchSafe does not claim

A scan reports what it covered and what it did not. A scan that finds nothing new is not proof that nothing is there, and LaunchSafe never calls anything compliant or certified. Reports are evidence for your own review: LaunchSafe is not an auditor.

Next

On this page