///  PRE-FLIGHT SECURITY FOR VIBE-CODED SOFTWARE

AI shipped your app in a weekend. Attackers need an afternoon.

Launch Guard pentests, audits and inspects AI-coded web apps before someone else does. Tools handle the sweep — a human verifies every single finding. And if your app comes back clean, the invoice reads $0.

$0 IF CLEAN·$47 IF WE FIND SOMETHING·$97 DEEP AUDIT

ENGAGEMENT LOG ANONYMIZED REPLAY
TARGET my-saas-mvp.vercel.app
NO-GO

A REAL ENGAGEMENT, ANONYMIZED — TWO HOURS OF WORK CONDENSED TO SECONDS.

0+
AUDITS DELIVERED
0
FINDINGS SURFACED
0
CLEAN LAUNCHES · CHARGED $0
0H
MAX TURNAROUND
TRUSTED ON APPS BUILT WITH LOVABLE·CURSOR·V0·BOLT·REPLIT·WINDSURF·CLAUDE CODE
01WHY THIS EXISTS

AI optimizes for it works.
Attackers look for it works too well.

v0, Cursor, Lovable, Bolt and Claude Code build in an afternoon what used to take a team a quarter. They also paste live API keys into client bundles because the prompt said "make it work", write fetch() calls that never check who's asking, and trust any JSON that shows up at a webhook.

The model isn't malicious. It's indifferent — and your launch inherits that indifference. Most attackers don't need a zero-day. They need your app to be exactly as shipped.

9/10
OF THE AI-BUILT APPS WE'VE AUDITED CARRIED AT LEAST ONE CRITICAL OR HIGH FINDING. THE TENTH GOT A CERTIFICATE AND A $0 INVOICE.
02PROTOCOL

Three steps.
No meetings.

You paste a link. We break things on purpose. You get a verdict you can act on — in writing, within 1 hour.

01

Hand over the target

Send the live URL of your deployed app. On the $97 track, add read-only repo access and we go after the source too. No scoping calls, no discovery phase, no "let's circle back" — you paste a link, we start breaking things.

URL — $0 / $47 TRACK URL + REPO — $97 TRACK
02

We attack it like it owes us money

Recon, auth abuse, injection batteries, secret scraping, IDOR crawling, payment-flow manipulation, business-logic probes, dependency CVEs — the same playbook a bored attacker runs on a Tuesday, except documented, human-verified, and pointed at you on purpose.

RECONAUTHZINJECTIONSECRETSLOGICDEPS
03

You get the verdict

Clean? You pay $0 and receive a signed clean-launch certificate — several founders put it straight in their changelog. Findings? A flat $47 unlocks the full report: every vulnerability, proof-of-concept, severity rating and exact fix guidance for your stack.

CLEAN → $0 FINDINGS → $47 FLAT
03FINDINGS INDEX

What we keep
finding.

Ten vulnerability classes we hit over and over in vibecoded apps, roughly in order of how often. Click any row — and remember this is a fraction of the checklist.

! HOW IT SHIPS

You asked the AI to "add payments" or "make it call GPT". It did — from the browser, with your live key inlined into public JavaScript. It works perfectly. For everyone.

! WHAT IT COSTS YOU

Drained quotas, five-figure cloud bills, and a key-rotation fire drill at 2 a.m. — usually announced by a stranger on X.

SEEN INv0 · Cursor · Bolt
! HOW IT SHIPS

"It works" meant the AI tested it while you were logged in. It never wrote the check that the requester is you — so /api/admin/* happily answers anyone who knows the path.

! WHAT IT COSTS YOU

Full account takeover of every user, one curl away. The most common critical we issue, by a wide margin.

SEEN INLovable · Cursor · Replit
! HOW IT SHIPS

Stripe told the AI to listen for a webhook. The AI listens — and trusts. Whatever JSON arrives at /webhook is accepted as gospel, signature never checked.

! WHAT IT COSTS YOU

Free checkout for anyone who reads the payment provider's docs. Your MRR becomes a suggestion.

SEEN INLovable · Bolt · v0
! HOW IT SHIPS

/api/invoices/1047 works for you — and for 1048, 1049, and every other user's data. The model never assumes the ID in the URL belongs to someone else.

! WHAT IT COSTS YOU

One scraped user list away from a breach disclosure you have to write yourself.

SEEN INAll of them, without exception
! HOW IT SHIPS

The AI string-concatenates your search box into a query because it was the simplest thing that compiled on the first try.

! WHAT IT COSTS YOU

Whole-database exfiltration — users, hashed passwords, and that .env you forgot was in the dump.

SEEN INCursor · Claude Code · Bolt
! HOW IT SHIPS

The key got committed, then "removed" in the next commit. Git remembers everything — and so does GitHub's search bar.

! WHAT IT COSTS YOU

Repo-scraping bots typically find public secrets within hours. This one is only visible on the $97 deep audit — HEAD looks clean.

SEEN INAny repo, any tool
! HOW IT SHIPS

Fetch was throwing an error, so the AI added Access-Control-Allow-Origin: * — with credentials. Error gone. Door open.

! WHAT IT COSTS YOU

Any website on the internet can silently act as your logged-in user.

SEEN INv0 · Lovable
! HOW IT SHIPS

Your login endpoint answers unlimited attempts as fast as they arrive. Nothing was ever throttled, because nothing was ever asked to.

! WHAT IT COSTS YOU

Industrial-scale credential stuffing, plus a password-reset endpoint that doubles as a user-enumeration oracle.

SEEN INAll of them
! HOW IT SHIPS

deploy.zip, .env.bak, dumps/ — deployed alongside the static build, because they were in the folder.

! WHAT IT COSTS YOU

Credentials, database and source code in one convenient download, no login required.

SEEN INBolt · Replit · manual deploys
! HOW IT SHIPS

The AI pinned a package it saw in a 2022 answer. That package has children now — all of them CVEs.

! WHAT IT COSTS YOU

Known, weaponized exploits aimed at freshly-generated URLs that attackers scan for sport.

SEEN INAll of them
04TERMS OF ENGAGEMENT

Zero if clean.
Forty-seven if not.

No hourly rate. No per-severity fees. No "contact us for a quote." One condition, printed right on the invoice: you pay only when we find something.

LAUNCH GUARD
TERMS OF ENGAGEMENT
DOC № LG-047 · REV 3
SERVICETHE SCAN — full external audit
YOU PROVIDElive URL of the deployed app
TURNAROUND≤ 1 hours
IF 0 FINDINGS $0
— ONE CONDITION —
IF ≥ 1 FINDING $47

FLAT · ONE-TIME · THE ENTIRE REPORT. Every vulnerability, proof-of-concept, severity rating and stack-specific fix guidance. Unlimited findings — one bug or eleven, same price.

HUMAN-VERIFIED FINDINGS ONLY
NDA ON REQUEST · NO AUTO-SPAM
PAY ONLY IF
WE FIND SOMETHING
TRACK B — FOR THINGS THAT MATTER

THE DEEP AUDIT

$97

Everything in THE SCAN — plus the repository. You provide the live URL and read-only code access, and the code gets read line by line by a person who does this for a living.

  • Secret history — every commit, not just HEAD
  • Route-by-route authorization map of the whole API
  • Dependency & supply-chain review, full CVE chain
  • Business-logic abuse cases: payments, invites, roles
  • Data-flow & injection deep-dive on the real code
  • Prioritized remediation plan, ordered by blast radius
— INCLUDES EVERYTHING IN THE SCAN —
FLAT · ONE REPORT · ≤ 1H · REPO ACCESS IS READ-ONLY & REVOKED AFTER

IF WE CAN'T REPRODUCE IT BY HAND, IT'S NOT IN YOUR REPORT — NO SCANNER NOISE, EVER.

05FIELD REPORTS

From people who
almost got away with it.

250+ audits delivered. 1,847 findings surfaced. 26 apps came back clean — their founders paid exactly $0 and got a certificate to prove it.

01 / 03
06QUESTIONS

Asked, answered.

The questions every founder asks before their first audit — and the honest answers.

You pay $0 — and you still get something: a signed clean-launch certificate listing what we tested and when. Several founders have put it straight into their changelog and pitch decks. It's the only invoice we're happy to send at zero.

It's not a pentest quote — it's a bet. We bet our time that we'll find something; you bet $47 that we won't. Most of the time we win the bet, and flat pricing means the report costs the same whether we find one bug or eleven. Volume keeps the number where it is.

Every finding with: a severity rating, a proof-of-concept you can reproduce yourself, what data or money it exposes, and fix guidance written for your actual stack — not generic advice. Plus a one-page summary verdict ordered by what to fix first.

Not on the $47 track — that's a black-box audit of the live app, exactly what an outside attacker sees. The $97 deep audit adds read-only repo access: secret history across all commits, route-by-route authorization, dependency chain and business-logic review.

Yes. NDA on request before we start, scoped credentials only (deleted after the audit), and findings go nowhere but to you. We sell reports, not disclosures — your bugs are your business.

1 hours max, usually under 30 minutes. You shipped in a weekend; we audit like it.

CLEAR FOR LAUNCH?

Paste your URL and hit the button. Worst case, you learn you're clean for $0. Best case, you learn it from us — instead of from a stranger with a scraper.

TRACK

NO MEETINGS · NO SCOPING CALLS · NDA ON REQUEST · TURNAROUND ≤ 1H