FAQ

Everything about LaunchGuard

How the scan works, how scoring and Verified work, what Fix costs, and what happens after you launch. If your question isn't here, run a free scan and see for yourself.

Scan & engine

A passive audit across fourteen areas: security headers, TLS and certificates, DNS and email security, exposed files and config, public storage, cookies and sessions, JavaScript secrets and source maps, frameworks and dependencies, admin interfaces and APIs, CORS and cross-origin policy, third-party scripts and supply chain, exposed API surface and documentation, subdomain takeover exposure, and lookalike domain protection.

Yes. It's entirely passive: no attacks, no malicious traffic, no contact with your users. It only reads what your app already exposes publicly.

Under a minute, and no account is needed to run a scan and see your score.

Any public URL. The scan only reads publicly available information, so you can check any site you're curious about.

AI security audits & vibe coding

Yes. LaunchGuard runs a passive AI security audit on AI-built apps: it reads what your app exposes publicly and scores it across fourteen categories. It is an external scan, not a penetration test and not a code review, so it sees what an outsider can reach, not your source or your backend logic.

Vibe coding is shipping software fast with AI build tools, often with no security team in the room. The gap is that those tools optimize for a working app, not a hardened one, so the same misconfigurations show up again and again: missing security headers, exposed config, weak email and DNS setup. LaunchGuard is built to catch that class of risk.

Paste your live URL and the scan runs, whatever you built it with. LaunchGuard reads the deployed app from the outside, so it works the same for a Vercel, Replit, Bolt, Lovable, or Cursor project. You get a Security Health Score and a report in under a minute, no account needed.

No, and we won't pretend otherwise. A passive external scan catches the common, high-frequency mistakes that AI-built apps ship with. It does not exploit anything, log in, or read your source code, so it is not a substitute for a full penetration test or a code audit. The methodology page spells out exactly where the limits are.

Your score

Each of the fourteen categories is scored from the evidence the scan collects. Those combine into one Security Health Score, 0 to 100, with a letter grade from A to F.

80 or above, with no open critical or high findings, earns LaunchGuard Verified. Below that, the report shows exactly what's holding you back.

The report

Yes. Register with your email and the full report unlocks immediately: every finding, its business impact, how to fix it, and an OWASP mapping. There's no charge for the report.

Each finding is tied to the matching OWASP category, the industry standard, so you and your engineers can see exactly what class of risk it represents.

Fix

When your report turns up real risk, a LaunchGuard security specialist works through it with you, one finding at a time, until a closing re-scan confirms you pass. It's a person doing the work with you, not a PDF of advice.

The price is sized to what your report actually finds, shown as an estimate up front. Your specialist confirms the exact price before you pay. It's a one-time fee per engagement, not a subscription.

No. Clear the findings yourself and you can go straight to Verified. Fix is there if you'd rather have a security professional guide you through it.

LaunchGuard Verified

No. The subscription is for everyone, whatever your score. It buys continuous monitoring and a live view of your climb toward the bar. The Verified badge is earned on top: it activates automatically the moment you pass (80 or above, no open critical or high findings). You subscribe to get watched and to climb; you earn the badge by passing.

$39 a month or $390 a year, with a 7-day free trial. That is the whole subscription: continuous monitoring, your climb toward the bar, and the Verified badge automatically once you pass.

Yes, that's the point. You subscribe now, we monitor and re-scan every day, and the badge activates by itself the moment your product passes the bar. If you later drop below the bar, the badge pauses and returns automatically when you pass again. Your subscription and monitoring continue throughout.

Verified gives you a public certificate page anyone can check, plus an embeddable badge you add with one snippet. The badge reflects your live status.

Cancel anytime from the billing portal. Your badge stays live until the end of the period you've already paid for.

Yes, that is much of what it is for: a public certificate anyone can check. Be clear on what it is, though. Verified is a passive external security scorecard, not a compliance certification. It is not SOC 2, ISO 27001, or a penetration test, and it does not assess your source code. It shows you passed LaunchGuard's audit at a given score, and that you keep passing.

After launch

LaunchGuard keeps re-scanning your app on a schedule and watching your certificate. When something changes that matters, you'll hear about it, in the app and by email.

It means you don't have to remember to re-check your security. LaunchGuard re-scans your app every day and only tells you when something material changes: a new finding, a score drop, a newly exposed service, an expiring certificate. Most days nothing changes and you hear nothing. It is included with a Verified subscription.

You choose. Every account controls which updates arrive in the app and which arrive by email, category by category.

Data & trust

LaunchGuard is a Swiss security platform built for how software ships now: fast, on AI build tools, often with no security team in the room.

Still deciding? The scan is free and takes under a minute.