The state of AI app security

What thousands of passive audits reveal about how AI-built software ships.

Anonymized benchmarks across every product LaunchGuard has scanned. No individual product is identifiable. How we scan →

60
AVG SCORE
across 2203 audits
Grade distribution
A
0 · 0%
B
281 · 13%
C
916 · 42%
D
886 · 40%
F
120 · 5%
Top security mistakes
Permissions-Policy header absent78%
No security.txt file published63%
Referrer-Policy header absent63%
X-Frame-Options header absent62%
X-Content-Type-Options header absent56%
No DKIM selector found among probed selectors41%
Weakest categories
Security headers
40
DNS & email security
49
Admin interfaces & APIs
66
API surface & documentation
72
Frameworks & dependencies
74
Brand & domain protection
75
Security by hosting platform
Average Security Health Score of apps we've scanned, grouped by where they're hosted and served.
Netlify
6642 scans
Vercel
65617 scans
Fly.io
6411 scans
Replit
635 scans
GitHub Pages
6012 scans
Railway
5711 scans
Render
5613 scans
Lovable
514 scans
Security by build tool
Average Security Health Score grouped by the AI tool founders built with. Self-reported by 6 founders so far.
Something else
597 scans
Remy by MindStudio
556 scans
Average score over time
2026-062026-08
37critical
3610high
6746medium
11426low
3404info
How does your product compare?
Run a free passive scan and find out in under a minute.
Run a free scan