AI operations
AI features that quietly run up the bill — runaway spend, retry loops, timeouts on long responses.
20 checks · 4 freeOWASP · API Sec · LLM Top 10 · ASVS · CWE
launchprep.
290 checks, grouped by what they cover. 117 run free on your machine — no account, no limit. The rest make up the deep scan in the $29 tier.
A check that cannot apply to your project is skipped and named in your report. Each maps to the standard it enforces — the OWASP Top 10, the API Security Top 10, ASVS and CWE — and to the privacy law that reaches your users.
Most scanners run everything and leave you to sort it out. Launchprep works out what you built first — the framework, whether there is a database, whether people can sign in, whether money or AI is involved, and where your users are — then runs only the checks that can apply. A static portfolio is asked around fifty questions; a multi-tenant SaaS taking payments is asked three times as many.
Anything that cannot apply is skipped and named in your report, with the reason. That list is the part worth reading: “forty-seven checks skipped, you are not multi-tenant” is what makes the twelve that did fire worth believing.
Each finding names the consequence in plain English — “any logged-in customer can read every other customer’s invoices”, not “missing authorization predicate” — and carries a file, a line and the fix. They are written for the person who built the app, not for a security engineer.
The free checks are the ones a program can settle on its own: a leaked key, a missing index, an absent security header, a cookie without a flag. They run on your machine, unlimited, and upload nothing. The rest need something to read the code and reason about it — whether one customer can reach another’s data, whether deleting an account really deletes it, whether a refund path can be replayed. Those are the deep scan.
AI features that quietly run up the bill — runaway spend, retry loops, timeouts on long responses.
20 checks · 4 freeOWASP · API Sec · LLM Top 10 · ASVS · CWEWhat breaks the first time real people show up — empty states, error handling, the paths you never tested as the only user.
20 checks · 8 freeOWASP · API Sec · ASVS · CWE · GDPRDjango settings that are safe in development and dangerous in production — DEBUG, ALLOWED_HOSTS, forced SSL, secure cookies.
18 checks · 13 freeOWASP · API Sec · ASVS · CWEThe gap between “works on my machine” and “survives a deploy” — migrations, rollbacks, secrets, graceful shutdown.
18 checks · 11 freeOWASP · API Sec · ASVS · CWERails defaults that bite in production — mass assignment, unsafe HTML rendering, exposed credentials, forced SSL.
15 checks · 11 freeOWASP · API Sec · ASVS · CWEQueries that are fine at fifty users and fall over at five thousand — unbounded lists, missing indexes, connection limits.
15 checks · 9 freeOWASP · API Sec · ASVS · CWE · GDPRNext.js App Router and API routes without the usual holes — server secrets, route timeouts, loading states, caching.
14 checks · 7 freeOWASP · API Sec · ASVS · CWEKeeping one customer’s data walled off from another’s — tenant-scoped queries, role and seat limits, cross-tenant access.
14 checks · 2 freeOWASP · API Sec · ASVS · CWE · GDPRThe API mistakes attackers probe first — missing authorization, over-fetching, unvalidated input, verbose errors.
14 checks · 9 freeOWASP · API Sec · ASVS · CWEPrompt injection, jailbreaks, and untrusted text reaching your AI features — the risks that arrive the moment users can type.
13 checks · 4 freeOWASP · API Sec · LLM Top 10 · ASVS · CWE · GDPRSupabase set up so your database is not open to the world — row-level security, exposed keys, storage rules.
12 checks · 3 freeOWASP · API Sec · ASVS · CWELetting users upload files without uploading trouble — type and size limits, storage isolation, dangerous paths.
12 checks · 6 freeOWASP · API Sec · ASVS · CWE · GDPRWhat happens to data over time — deletion and the right to erasure, retention, backups, orphaned records.
12 checks · 0 freeOWASP · ASVS · CWE · GDPRThe production basics that stay invisible until they fail — TLS, security headers, backups, resource limits.
11 checks · 3 freeOWASP · API Sec · ASVS · CWESign-in that cannot be walked around — session handling, password rules, reset flows, brute-force limits.
10 checks · 5 freeOWASP · API Sec · ASVS · CWE · GDPRThe privacy and legal footing a public app needs — a policy, consent, and handling data the law reaches.
10 checks · 3 freeASVS · GDPRBeing ready for the day something goes wrong — a security contact, searchable logs, a way to respond.
10 checks · 1 freeOWASP · API Sec · ASVS · GDPRMobile checks before the store review — permissions, secrets in the binary, transport security.
10 checks · 3 freeOWASP · ASVS · CWE · GDPRAPI keys and tokens where they do not belong — the browser bundle, the repository, the logs.
9 checks · 7 freeOWASP · API Sec · LLM Top 10 · ASVS · CWEMaking sure a signed-in user can only reach their own data — object-level access, admin routes, privilege checks.
8 checks · 1 freeOWASP · API Sec · ASVS · CWETaking money without leaving holes — webhook verification, idempotency, amounts a customer cannot tamper with.
8 checks · 2 freeOWASP · API Sec · ASVS · CWEStopping one user from overwhelming everyone else — limits on logins, password resets, and expensive endpoints.
7 checks · 1 freeOWASP · API Sec · LLM Top 10 · ASVS · CWEThe rough edges real users hit — broken links, missing feedback, forms that fail silently.
6 checks · 2 freeAPI Sec · ASVSSeeing what your app does in production — error tracking, logs, and alerts that actually reach you.
4 checks · 2 freeOWASP · ASVS · CWESomething missing? The checks come from real launches going wrong. If you know one we do not cover, add it to the list — it becomes a check every builder gets.
Run every check that applies to your project, on your machine, free and unlimited:
npx launchprep