Launchprep launchprep.
readiness scan for AI-built apps

Your AI-built app works.
That doesn’t mean it’s ready to launch.

Launchprep finds what breaks a launch while it’s still yours to fix — before customers or regulators do.

A pre-launch checklist and security scanner — for apps built with Cursor, Claude Code, Lovable, v0, Bolt or Replit, and for the ones you wrote yourself.

Mapped to OWASP Top 10 · API Security Top 10 · LLM Top 10 · ASVS · CWE · SOC 2 · GDPR

One command. Four things happen. No signup. No dashboard. Nothing living in your repo.

01
Reads your code

Every file, on your machine.

$ npx launchprep
1,847 files · 0.4s
02
Works out what you built

Stack, accounts, shared database, payments, where users live. Shown, so you can correct it.

express · postgres · vercel
tenancy shared · ai anthropic
03
Runs only what fits

The rest are skipped and listed with the reason.

95 apply · 155 skipped
39 more need 3 answers
04
You fix it and run it again

Each finding carries a file, a line and the fix.

api/invoices/route.ts:14
CRITICAL no ownership check

Mapped to published standards, not name-dropped. Every check carries its place in the OWASP Top 10, the API Security Top 10, ASVS and CWE — and the privacy law where your users actually are.

THE PROBLEM
5,000

vibe-coded apps found leaking sensitive data in a scan of 380,000. RedAccess, May 2026

  • 1.5M API authentication tokens, 35,000 email addresses and private messages exposed by one misconfigured database Moltbook, found by Wiz
  • 170+ production AI-built applications shipped with row level security missing CVE-2025-48757, CVSS 9.3
THE STANDARDS
Mapped, not name-dropped
  • All ten OWASP Top 10 categories — 133 checks
  • 98 checks on the OWASP API Security Top 10
  • 19 built for AI apps — prompt injection to spend ceilings
  • 141 carry CWE identifiers; 163 map to ASVS chapters
  • 23 flag practices GDPR forbids; 77 cover ground SOC 2 auditors ask about

Asks where your users are, then applies only the law that reaches them. Every finding names its rule.

THE PROOF
Tested before it ships
  • Run against 68 production codebases in six languages
  • A check must fire on broken code and stay silent on correct code
  • 166 false alarms removed in tuning. A scanner that cries wolf is worse than none

Why not just ask your agent? You can, and you should. This is the part that is hard to ask for.

01

Asking is easy. Knowing what to ask is not.

“Review my code for security” returns the top ten. Never whether deleting an organisation orphans its customers’ documents — a real finding, in a real repository.

02

Findings without a denominator are a feeling.

A chat window never tells you what it did not look at. This names the 155 it skipped, and why — and that list is the part you can audit.

03

Says when it cannot tell.

39 checks it could not settle without asking you. A confident wrong answer costs more than an honest gap.

Same AI underneath. You are buying the 290 questions — asked in full, in the same order, every time.

One price, paid once. You launch once — not monthly. No subscription, no seats, no sales call. The free half stays free with or without a key.

FREE FOREVER $0
117 checks a program can settle on its own.
  • Unlimited scans, no account
  • Every finding with a file, a line and the fix
  • The skipped list, with reasons
$ npx launchprep
EVERYTHING $29 once
173 more that need judgement, not pattern matching.
  • Authorization, tenant isolation, deletion and money — mapped to OWASP ASVS, chapter by chapter
  • 5 deep scans that remember — each picks up where the last one stopped
  • A dated report at a link you can send a client
  • A CI gate that fails the build, not warns
  • A year of new rules as frameworks change
Buy — $29 pay → key by email → npx launchprep login See a real report first →