Skip to content

Learn

Plain words for the whole glossary

44 terms that turn up on a result or in the work around it. No jargon defined with more jargon. Each one links to the findings and incidents where it matters.

Running it confirms you own this app or are authorized to test it. ShipReady reads its public pages and JavaScript bundles.

44 termsLast updated September 13, 2026
  • Term

    Anon key

    The public browser key. Safe to publish, useless without rules behind it.

  • Term

    Batch prompt

    One instruction that fixes several findings in a single pass.

  • Term

    Claim token

    The unguessable string that lets you attach an anonymous result to your account later.

  • Term

    Content-Security-Policy

    The header that tells the browser which code it is allowed to run.

  • Term

    Cookie flags

    The three settings that decide how safely a cookie travels.

  • Term

    Cost cap

    The ceiling that stops one visitor spending your month's budget in an hour.

  • Term

    Could not check

    The request failed, so there is no result for that item.

  • Term

    Cross origin rules

    The header that decides which other sites may read your responses.

  • Term

    Declared

    Something you told us, recorded as your statement rather than our finding.

  • Term

    Detected

    Something the check worked out about your app without being told.

  • Term

    DMARC

    The record that tells receiving servers what to do when mail fails your checks.

  • Term

    Domain expiry

    The date your domain registration runs out, published in the registry.

  • Term

    Entitlement

    The record that says this account paid for this thing.

  • Term

    Fingerprint

    What your app quietly tells the internet about how it was built.

  • Term

    Fix prompt

    A ready instruction for the tool that built your app.

  • Term

    frame-ancestors

    The rule that stops another site putting your app inside an invisible frame.

  • Term

    Hardening Sprint

    The $1,750 engagement that takes the top items from needs fix to fixed and re-verified.

  • Term

    HSTS

    The header that tells browsers to never speak to your site over plain HTTP again.

  • Term

    Idempotency

    Doing the same thing twice has the same effect as doing it once.

  • Term

    Launch Review

    The $199 review where a named person looks at what a URL cannot see.

  • Term

    Launch Risk Statement

    A dated page saying what was observed, what was declared, and what nobody verified.

  • Term

    Not verified

    Named items nobody checked, listed rather than quietly dropped.

  • Term

    Observed

    Something a check actually read from your published app, with the evidence attached.

  • Term

    Open signup

    Whether anyone can create an account, and whether the address has to be proved.

  • Term

    Prompt injection

    Text your app feeds to a model that the model treats as instructions.

  • Term

    Publishable key

    The newer name for a public client key. Same rule: public by design, not a permission.

  • Term

    Rate limit

    The rule that slows down whoever is asking too often.

  • Term

    Release Assurance

    The monthly option that keeps a current statement for teams shipping every week.

  • Term

    Release Gate

    The $49 package that hands you the checklist and the guardrails to fix things yourself.

  • Term

    Rollback

    Putting the previous version back, quickly, when the new one is wrong.

  • Term

    Row level security

    The rule that decides which rows of a table an account may read or change.

  • Term

    Security definer

    A database function that runs with its author's permissions rather than the caller's.

  • Term

    Service role key

    The key that ignores every access rule. It belongs on a server and nowhere else.

  • Term

    Slopsquatting

    Registering the package names AI tools invent, and waiting.

  • Term

    Source map

    The file that turns your shipped bundle back into readable source.

  • Term

    SPF

    The DNS record naming who is allowed to send email as your domain.

  • Term

    Staleness

    How out of date an observation is, stated rather than hidden.

  • Term

    Storage bucket

    The place uploaded files live, and the setting that decides who can read them.

  • Term

    Tenant isolation

    One customer's data staying entirely out of another customer's account.

  • Term

    Trust Center

    A published page that answers the security questions buyers ask.

  • Term

    Webhook signature

    Proof that the message really came from the service that claims to have sent it.

Check your app

Run all sixteen groups on your published address and see the evidence behind every result.

Running it confirms you own this app or are authorized to test it. ShipReady reads its public pages and JavaScript bundles.

ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.

Last updated September 20, 2026