Introduction
LaunchSafe finds security problems in your code, shows the evidence, opens fix pull requests for you to approve, and proves the fix with a retest.
LaunchSafe is security testing for software teams. When repository scans open, you connect a GitHub repository, LaunchSafe's AI agents look for vulnerabilities in the code, and you get findings with evidence, fix pull requests you approve, and reports a customer or auditor can check.
What you can do today
- Grade a public repository for free. No account needed. See the public grade.
- Scan a repository (when scans open). Link a GitHub repository to a project, see the price in credits first, and start a code scan. A scan looks at the code, its dependencies and secrets committed to it. See scan types.
- Read findings with evidence. Each finding says what is wrong, where, how it was proven, and how to fix it. See findings.
- Fix with a pull request you approve. LaunchSafe writes the fix and shows it to you. Nothing is pushed to GitHub until you approve. See fix pull requests and retests.
- Check the fix. A retest decides whether a finding is fixed. Only a retest closes a finding.
- Issue signed reports. Anyone holding a report file can check it on a public page without an account. See signed reports.
- Connect Supabase. A read-only check turns your Supabase project's security settings into findings. See Supabase.
- Work where your team works. Slack, Jira and Linear are supported. See integrations.
How a scan will work
This is how repository scans work when they open for your organization.
Link your code
Connect GitHub and link a repository to a project.
Get a quote
Choose a depth and see the cost in credits before anything starts.
Scan
LaunchSafe's engine analyzes the code. You can cancel a running scan.
Review and fix
Triage findings, ask for a fix, approve the pull request, merge it.
Retest and report
A retest confirms the fix. Then issue a report if you need one.
What LaunchSafe does not claim
A scan reports what it covered and what it did not. A scan that finds nothing new is not proof that nothing is there, and LaunchSafe never calls anything compliant or certified. Reports are evidence for your own review: LaunchSafe is not an auditor.