https://shipreadyai.dev/compare/reeve

> Discover all available pages from the documentation index at https://shipreadyai.dev/llms.txt

# ShipReady vs Reeve

A research-led scanner that has published a large-scale sweep of AI-built apps.

# ShipReady vs Reeve
A research-led scanner that has published a large-scale sweep of AI-built apps.
Facts about Reeve were read from their site on the dates shown. Tell us if something changed.
## Score or evidence
- **Them.** The public write-up reports finding categories and counts across the sample rather than a per-app score. Source: https://reeve.page/ (read 2026-09-14).
- **Us.** No score, no grade, no badge. Every finding shows the request that produced it and the date it was read.
## What they show and what they keep
- **Them.** The research report is public. The public pages do not describe a self-serve scan for arbitrary URLs. Source: https://reeve.page/ (read 2026-09-14).
- **Us.** The full free result is shown to anyone with the check id. Nothing is gated behind a paywall or an account.
## What they do to your app
- **Them.** Automated outside checks at research scale. The pages do not describe signing in as your users or executing your database functions. Source: https://reeve.page/ (read 2026-09-14).
- **Us.** Deterministic outside requests only. Never signs in, never executes a function on your database, never reads another account's data.
## What neither can see from outside
- **Rollback and recovery.** Whether you can put the previous version back, and how long that takes.
- **Error monitoring.** Whether a failure in production reaches a human rather than sitting in a log nobody opens.
- **Sign in and account flows.** Whether sign in, password or code reset, and session expiry behave under real use.
- **Rate limiting and abuse controls.** Whether a script can hammer your forms, sign up loop, or paid endpoints without being slowed down.
- **Key rotation.** Whether you can replace a leaked key quickly and know everywhere it is used.
- **Certificate expiry date.** Whether the certificate is close to expiring. A normal request proves the certificate is valid right now, and the runtime this check uses cannot read the expiry date from that request.
- **One account reading another account's data.** Whether a signed in account can reach another account's records by changing an id. ShipReady does not create accounts, sign in, or call your functions, so this cannot be answered from outside.
- **Payment handling.** Whether payment events are verified, replay safe, and matched to the right customer record.
- **Customer data handling.** Whether stored personal details are limited, deletable on request, and out of your logs.
- **AI feature controls.** Whether prompts, spend, and model output are bounded so one visitor cannot run up the bill.
- **Database row rules.** Whether the row rules behind the app actually stop one signed in account reading another's rows.
## Fixes
- **Them.** The report describes issue categories rather than per-builder fix prompts. Source: https://reeve.page/ (read 2026-09-14).
- **Us.** Every finding carries five fix prompts for Lovable, Bolt, Base44, v0 and generic coding assistants, hand written per finding.
## Beyond security
  - Legal page links: them no, us yes
  - Email authentication: them no, us yes
  - Domain expiry: them no, us yes
  - Cookie flags: them no, us yes
  - Platform trust evidence: them no, us yes
  Source: https://reeve.page/
## What happens next
- **Them.** Read the report and cross reference the categories against your own build. Source: https://reeve.page/ (read 2026-09-14).
- **Us.** You can stop at the free check, or buy the Release Gate at $49 for the package, the Launch Review at $199 for a person, or the Hardening Sprint at $1,750 for the fix work.
## Competitor strengths
A public research report that puts numbers on how AI-built apps fail at scale, which is useful evidence for anyone shipping in this category.
## Choose them if
You want a public research report to reference when you make the case for taking launch checks seriously, and you are not looking for a self-serve URL scan.
## How our checks map to theirs
Reeve's report scanned 30,998 AI-built apps and grouped the failures they saw. Our sixteen check groups line up with the same recurring categories: exposed keys and server credentials in client code (their leaked secrets), open database rules and readable rows (their access control failures), public storage buckets and Firebase collections (their exposed storage), missing security headers and transport issues (their transport misconfiguration), and open sign-up with no confirmation (their account controls). Where the report names a class of failure, our check names the same class in the finding it produces.
## Sources
- https://reeve.page/

