FAQ
Answers to common questions about what LaunchSafe does today, how fixes and retests work, and what it does not do yet.
General
Today it grades public GitHub repositories for free and checks Supabase project settings. Repository scans for your organization are not open yet; when they open, LaunchSafe returns findings with evidence, opens fix pull requests you approve, retests fixes, and issues signed reports. See the introduction.
Not yet. Live-app testing is not open, and repository scans for your organization aren't open yet either. You can prove you control a domain now. See domain verification.
Sign-up is invite-only for now. Request access. See create an account.
No. A scan reports what it covered, and a scan that finds nothing new is not proof that nothing is there. Each scan lists what it did not cover.
Scans
It depends on the repository. Each depth has a longest run time: quick up to 60 minutes, standard up to 6 hours, deep up to 24 hours.
Yes, while it is running.
GitHub. GitLab and Bitbucket can be connected and linked, but scans cannot fetch their code yet.
No. Neither is available.
Findings and fixes
No. Each finding shows a proof status: Needs review, Reproduced or Verified. Needs review is a suspicion until someone checks it.
No. A fix is shown to you first and nothing is pushed to GitHub until you approve it. The pull request opens as a draft by default and you merge it yourself. A project can be set to approve fixes automatically, and only if you grant write access.
Only a retest that covered the finding and found it fixed closes it. You can also mark it an accepted risk, with an end date, or a false positive, with a reason.
By email, one message per scan listing new critical findings, to members who can see the project. You can turn it off under Settings → Notifications. Slack, Jira and Linear are also supported.
Reports and trust
No. LaunchSafe is not an auditor. A report is evidence for your review: what was tested on which dates and what was found.
Yes. Every report has a signature and a verify ID, and anyone can check a file on the public verify page without an account. See signed reports.
Account and billing
No. You sign in with an email code, Google or GitHub, and can add two-step sign-in.
Not yet.
See plans and pricing.
Something missing? See contact and support.