# ShipReady > Launch assurance for AI-built apps ## What ShipReady is ShipReady is launch assurance for apps built with AI tools. It is run by TechTide AI, whose founder and CTO is Alex Cinovoj. Contact: Alex@techtideai.io. The free Launch Risk Check reads a public URL from the outside and reports what an ordinary visitor can observe: the redirect and certificate, protective response headers, source maps, secrets left in client JavaScript, exposed paths, cookies, email records and legal pages. It never signs in, never writes anything, and never reads the contents of a database. It does not claim an app is free of problems, and it produces no score and no badge. The paid tiers change what a Launch Risk Statement can say. Release Gate gives you the checklist and repo guardrails to resolve findings yourself. Launch Review adds a dated written verdict from a named reviewer covering the items the free check leaves as not verified. The Hardening Sprint takes the highest priority items from needs fix to fixed and re-verified. Release Assurance keeps a current statement for teams that ship every week. ## What the check never claims - It never says an app is free of problems. - It never produces a score, a grade, a badge or a certificate. - It never signs in, never writes anything and never reads the contents of a database. - It never treats a declared answer as something it verified. - It is not a penetration test. - It runs only on an app the requester owns or is authorized to test. ## The four statuses - Observed: the check saw this from outside, and the evidence line says what it saw. - Declared: the owner stated this about their stack, payments, data or AI features. It is input, not verification. - Not verified: no check of a public address can see this. It is not a pass and not a failure. - Could not check: the attempt did not produce a reliable result, and the reason is written out. ## The sixteen checks - o1: how the site is served - o2: response headers - o3: for source maps - o4: bundles for secrets - o5: what the app is built with - o6: common private paths - o7: platform trust evidence - o8: database table access - o9: cookies - o10: mail records - o11: legal pages - o12: file storage - o13: cross origin rules - o14: the domain registration - o15: Firebase endpoints - o16: backend sign in settings ## Findings are grouped for the reader - Fix before launch. - Fix this week. - Good to know. - Passed. - Could not check. ## Products - Free Launch Risk Check. $0. An external read of one public URL, with evidence and a date on every line. No account. Results in about twenty seconds. - Release Gate. $49. The launch checklist and repo guardrails you install yourself. - Delivery: In your library the same minute. - Refund: Refundable within 7 days of purchase. - Launch Review. $199. A written review of your production layer plus a recorded walkthrough. - Delivery: First reply within 1 business day. Delivered within 3 business days. - Refund: Refundable in full any time before work starts. - Hardening Sprint. $1,750. Seven business days of paired work on the highest priority fixes. - Delivery: Written scope within 2 business days, then 7 business days of work. - Refund: Refundable in full any time before scope confirmation. - Release Assurance. $3,500 per month. Four release-risk reviews a month, one architecture clinic, priority triage, and maintained repo guardrails for teams that ship weekly. - Delivery: Onboarding call within 3 business days, first review within 5. - Refund: Cancel monthly. Access runs to the end of the paid period. - Re-verification. $99. A fresh verdict on the items marked Needs fix on your statement, after you have made the changes. - Delivery: First reply within 1 business day. New verdicts within 2 business days. - Refund: Refundable in full any time before work starts. ## Credits between products - The 199 dollars paid for a Launch Review is credited toward a Hardening Sprint booked within 30 days. - Every purchase requires sign in. The free check never does. - Sign in is an email one-time code. There is no password. ## Limits - Five checks per connection per hour. - The same address can be checked ten times in a day. - The same address checked again within 10 minutes returns the existing results instead of running again. ## Retention - Check records, including findings and declared answers, are kept for 90 days and then deleted. - Secrets are never stored. Row contents are never stored. - Payment records are held by Stripe under their own retention rules. No card numbers are stored here. - To have a record removed sooner, write to Alex@techtideai.io from an address connected to the app. ## Disclaimer ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure. ## Start here - [ShipReady](https://shipreadyai.dev/index.md): Launch assurance for AI-built apps. - [Launch Risk Check](https://shipreadyai.dev/check.md): Paste your app's URL. We read what your customers can read. No account needed, results in about 20 seconds. - [Simple pricing](https://shipreadyai.dev/pricing.md): Three ways to deal with what the free check finds: Release Gate at $49, Launch Review at $199, and the Hardening Sprint at $1,750. - [What we check, and what we don't](https://shipreadyai.dev/what-we-check.md): The exact external checks ShipReady runs on a public URL, the things it never does, and how long check records are kept. - [About Alex Cinovoj](https://shipreadyai.dev/about.md): Alex Cinovoj is the founder of ShipReady and founder and CTO of TechTide AI. ## Product - Release Gate: $49. The launch checklist and repo guardrails you install yourself. In your library the same minute. Refundable within 7 days of purchase. Listed on the pricing page in Start here. - Launch Review: $199. A written review of your production layer plus a recorded walkthrough. First reply within 1 business day. Delivered within 3 business days. Refundable in full any time before work starts. Listed on the pricing page in Start here. - Hardening Sprint: $1,750. Seven business days of paired work on the highest priority fixes. Written scope within 2 business days, then 7 business days of work. Refundable in full any time before scope confirmation. Listed on the pricing page in Start here. - Release Assurance: $3,500. Four release-risk reviews a month, one architecture clinic, priority triage, and maintained repo guardrails for teams that ship weekly. Onboarding call within 3 business days, first review within 5. Cancel monthly. Access runs to the end of the paid period. Listed on the pricing page in Start here. - Re-verification: $99. A fresh verdict on the items marked Needs fix on your statement, after you have made the changes. First reply within 1 business day. New verdicts within 2 business days. Refundable in full any time before work starts. Listed on the pricing page in Start here. - [Production readiness checklist for AI-built apps](https://shipreadyai.dev/production-readiness-checklist.md): A production readiness checklist for AI-built apps: transport, headers, exposed files, data access, payments and operations, and what an outside check confirms. - [Contact ShipReady](https://shipreadyai.dev/contact.md): Contact Alex Cinovoj about a check, purchase, review, or launch question. ## Free tools - [Free tools](https://shipreadyai.dev/tools.md): Five free single purpose checks: security headers, source maps, email authentication, backend table exposure and package names. Each one runs part of the full Launch Risk Check. - [Security headers check](https://shipreadyai.dev/tools/security-headers.md): Read the response headers on your published app: HSTS, Content-Security-Policy, frame protection, referrer policy and permissions policy. Evidence and a fix prompt, no account. - [Source map exposure check](https://shipreadyai.dev/tools/source-maps.md): Find out whether your published JavaScript bundles still point at source maps, and what those maps hand to anyone who asks for them. Evidence and a fix prompt, no account. - [Email authentication check](https://shipreadyai.dev/tools/email-authentication.md): Check the SPF and DMARC records on your app's domain, the records that decide whether your password reset lands in the inbox and whether a stranger can send mail as you. - [Backend exposure test](https://shipreadyai.dev/tools/supabase-exposure.md): Ask your own backend, with the key your app already publishes, which tables, file buckets and collections answer an anonymous request, and what your sign in settings allow. Names and counts only, never the contents of a row or a file. - [Package name check](https://shipreadyai.dev/tools/package-check.md): Paste your dependency list and find out which package names have no published package behind them. The answer is the public registry's own status code, with no account. ## Findings explained - [Every finding, explained](https://shipreadyai.dev/learn/findings.md): One page for each of the 67 findings the free check can report. - [Plain http traffic is sent on to https](https://shipreadyai.dev/learn/findings/o1-https-redirect-ok.md): Visitors who type the address without https land on the encrypted version instead of the plain one. - [Plain http traffic is not sent on to https](https://shipreadyai.dev/learn/findings/o1-https-redirect-missing.md): Someone who reaches the plain http address stays on an unencrypted connection, so anything typed on that page travels in the clear. - [The https address did not answer cleanly](https://shipreadyai.dev/learn/findings/o1-tls-failed.md): Browsers show a warning page or refuse the connection, so most visitors never reach the app at all. - [The page loads some files over plain http](https://shipreadyai.dev/learn/findings/o1-mixed-content.md): Browsers block or downgrade these files, so parts of the page can break, and the padlock treatment is lost. - [Every file on the page loads over https](https://shipreadyai.dev/learn/findings/o1-mixed-content-ok.md): Nothing on the page is pulled over a plain connection. - [Strict-Transport-Security is set](https://shipreadyai.dev/learn/findings/o2-hsts-ok.md): Browsers remember to use https for this domain on later visits. - [Strict-Transport-Security is not set](https://shipreadyai.dev/learn/findings/o2-hsts-missing.md): A browser that has been to the site before can still be pushed to the plain http version on a hostile network. - [Content-Security-Policy is set](https://shipreadyai.dev/learn/findings/o2-csp-ok.md): The page tells the browser which sources of scripts and styles it will accept. - [Content-Security-Policy is not set](https://shipreadyai.dev/learn/findings/o2-csp-missing.md): If any injected markup reaches a page, the browser has no rule telling it which scripts it is allowed to run. - [The content policy allows inline scripts](https://shipreadyai.dev/learn/findings/o2-csp-unsafe-inline.md): The script-src rule includes unsafe-inline, which removes most of the protection the policy would otherwise give. - [X-Content-Type-Options is set](https://shipreadyai.dev/learn/findings/o2-x-content-type-options-ok.md): Browsers will not guess a file type that differs from the one you declared. - [X-Content-Type-Options is not set](https://shipreadyai.dev/learn/findings/o2-x-content-type-options-missing.md): A browser may treat an uploaded or user supplied file as a script because it guesses the type. - [Framing is restricted](https://shipreadyai.dev/learn/findings/o2-frame-protection-ok.md): Other sites cannot silently place your pages inside their own. - [Framing is not restricted](https://shipreadyai.dev/learn/findings/o2-frame-protection-missing.md): Another site can load your pages inside an invisible frame and trick a signed in visitor into clicking things they cannot see. - [Referrer-Policy is set](https://shipreadyai.dev/learn/findings/o2-referrer-policy-ok.md): Outbound links do not carry the full address of the page the visitor came from. - [Referrer-Policy is not set](https://shipreadyai.dev/learn/findings/o2-referrer-policy-missing.md): Full page addresses, including anything you put in a path or query string, are sent to third party sites your pages link to or load from. - [Permissions-Policy is set](https://shipreadyai.dev/learn/findings/o2-permissions-policy-ok.md): Camera, microphone, and location access are limited to what you named. - [Permissions-Policy is not set](https://shipreadyai.dev/learn/findings/o2-permissions-policy-missing.md): Embedded third party frames can ask for camera, microphone, or location on your domain's behalf. - [Source maps are published next to the app code](https://shipreadyai.dev/learn/findings/o3-source-maps.md): Anyone can rebuild your original files, including comments, file names, and any logic you assumed was hidden. - [No published source maps were reachable](https://shipreadyai.dev/learn/findings/o3-source-maps-ok.md): The bundles checked did not resolve to a readable source map. - [A server side key appears in code the browser downloads](https://shipreadyai.dev/learn/findings/o4-secret-in-bundle.md): Anyone who opens the page can read this key and use it directly against the service it belongs to, with your account paying for it. - [No server side keys matched in the downloaded code](https://shipreadyai.dev/learn/findings/o4-secret-none.md): The known server key patterns did not appear in the files checked. Publishable and browser keys are expected there and are ignored. - [What the outside of the app reveals](https://shipreadyai.dev/learn/findings/o5-fingerprint.md): Anyone can see this from a browser. It is listed so you know what is on show. - [A response header names a software version](https://shipreadyai.dev/learn/findings/o5-version-disclosure.md): Naming the exact version tells anyone scanning the internet which known issues to try first against your host. - [A file that should not be public answers on the live site](https://shipreadyai.dev/learn/findings/o6-exposed-path.md): This file usually carries configuration, keys, or repository history, and it is readable by anyone who asks for it. - [The common private files did not answer](https://shipreadyai.dev/learn/findings/o6-exposed-path-ok.md): Requests for configuration and repository files came back empty or missing. - [Public information files](https://shipreadyai.dev/learn/findings/o6-public-files.md): These files tell crawlers and researchers how to treat the site. - [The hosting platform publishes its own check results](https://shipreadyai.dev/learn/findings/o7-trust-evidence.md): The platform reports the following checks for this app: {checks}. - [Some database tables answer without anyone signing in](https://shipreadyai.dev/learn/findings/o8-tables-exposed.md): A request made with the browser key alone returned rows, which means the row rules on those tables let anonymous readers in. - [The table list is not readable without signing in](https://shipreadyai.dev/learn/findings/o8-schema-not-readable.md): An anonymous request could not list the tables behind the app. - [A cookie is missing a protective flag](https://shipreadyai.dev/learn/findings/o9-cookie-flags.md): A cookie without Secure can travel over a plain connection, and one without HttpOnly can be read by any script on the page. - [Cookies on the first response look fine](https://shipreadyai.dev/learn/findings/o9-cookies-ok.md): No cookie was set without its protective flags on this response. - [No cookies were set on the first response](https://shipreadyai.dev/learn/findings/o9-no-cookies.md): The landing response set no cookies, so there were no flags to check. - [An SPF record is published](https://shipreadyai.dev/learn/findings/o10-spf-ok.md): Mail servers can see which services are allowed to send using your domain. - [No SPF record is published](https://shipreadyai.dev/learn/findings/o10-spf-missing.md): Anyone can send mail that claims to come from your domain, and your own mail is more likely to land in spam. - [A DMARC record is published](https://shipreadyai.dev/learn/findings/o10-dmarc-ok.md): You have told receiving servers what to do with mail that fails the checks. - [No DMARC record is published](https://shipreadyai.dev/learn/findings/o10-dmarc-missing.md): Receiving servers have no instruction for mail that fails the checks, so forged mail from your domain is more likely to be delivered. - [Mail records were not checked for this address](https://shipreadyai.dev/learn/findings/o10-shared-domain.md): The app is on a shared hosting domain ({domain}), so its mail records belong to the platform and not to you. - [A privacy page is linked](https://shipreadyai.dev/learn/findings/o11-privacy-ok.md): Visitors can find how their information is handled. - [No privacy page is linked](https://shipreadyai.dev/learn/findings/o11-privacy-missing.md): Payment providers, app stores, and several privacy laws expect a reachable privacy page before you take anyone's details. - [A terms page is linked](https://shipreadyai.dev/learn/findings/o11-terms-ok.md): Visitors can find the rules of using the product. - [No terms page is linked](https://shipreadyai.dev/learn/findings/o11-terms-missing.md): Without stated terms you have no written basis for suspending misuse or limiting your liability. - [A refund or returns page is linked](https://shipreadyai.dev/learn/findings/o11-refunds-ok.md): Buyers can see the refund position before they pay. - [No refund or returns page is linked](https://shipreadyai.dev/learn/findings/o11-refunds-missing.md): Card processors expect a stated refund position, and disputes are harder to answer without one. - [Functions callable by name from the public schema](https://shipreadyai.dev/learn/findings/o8-rpc-functions.md): The public schema names {total} functions callable by name: {functions}. Whether each checks authorization needs a code review. ShipReady lists the names and never calls them, which is why backend rules stay on the not verified list. - [The storage bucket list answers without a sign in](https://shipreadyai.dev/learn/findings/o12-buckets-listable.md): A request with the browser key returned the names of {total} storage buckets: {buckets}. Names alone give a reader the shape of what you store. - [Some storage buckets are readable by anyone with the address](https://shipreadyai.dev/learn/findings/o12-bucket-public.md): These buckets are marked public, so any file inside one can be read by anyone who knows or guesses its address: {buckets}. - [Storage buckets list their objects without a sign in](https://shipreadyai.dev/learn/findings/o12-objects-listable.md): An object list request carrying only the browser key came back from these buckets: {buckets}. The counts show how much is behind each name. ShipReady records names and counts and never keeps an object name or a file. - [Files in a listing bucket open without a session](https://shipreadyai.dev/learn/findings/o12-objects-readable.md): One object address from each of these buckets answered a plain request with no session: {buckets}. Anything stored there can be read by anyone who can list it. - [Storage did not answer an anonymous request](https://shipreadyai.dev/learn/findings/o12-storage-ok.md): The bucket listing did not come back to a request holding only the browser key. - [Any site can read your responses with a visitor's session](https://shipreadyai.dev/learn/findings/o13-cors-open-credentials.md): {path} answered a request from an outside origin with an allow origin of {origin} and credentials allowed, so a page on another domain can read responses using your visitor's session. - [Cross origin reads are open to every site](https://shipreadyai.dev/learn/findings/o13-cors-wildcard.md): {path} answered with an allow origin of {origin}, so any site can read what it returns. Without credentials that is only a problem for data you did not mean to publish. - [Cross origin rules are narrow or absent](https://shipreadyai.dev/learn/findings/o13-cors-ok.md): A request from an outside origin came back without a header inviting other sites to read the response. - [The domain registration comes up for renewal](https://shipreadyai.dev/learn/findings/o14-domain-renewal-due.md): The public registry record says {domain} expires on {expiry}, which is {days} days away. That is close enough to put a renewal on the calendar now. - [The domain registration expires soon](https://shipreadyai.dev/learn/findings/o14-domain-expiring.md): The public registry record says {domain} expires on {expiry}, which is {days} days away. An expired domain takes the app, the mail, and the sign in links with it. - [The domain registration has time left](https://shipreadyai.dev/learn/findings/o14-domain-ok.md): The public registry record says {domain} expires on {expiry}, {days} days away. - [The app runs on a shared platform domain](https://shipreadyai.dev/learn/findings/o14-domain-shared.md): {domain} belongs to the hosting platform, so there is no registration of yours to expire and no registry record to read. - [The Firebase database answers without a sign in](https://shipreadyai.dev/learn/findings/o15-firebase-database-open.md): A plain request to {endpoint} returned data with no sign in, so the rules on that database let anonymous readers in. - [Firebase storage listed its contents without a sign in](https://shipreadyai.dev/learn/findings/o15-firebase-storage-open.md): A plain request to {endpoint} returned an object listing with no sign in, so anyone can enumerate what is stored. - [Firestore collections answer without a sign in](https://shipreadyai.dev/learn/findings/o15-firestore-open.md): Requests with no sign in came back with documents from these collections: {collections}. ShipReady records the collection names and the counts and never keeps a document. - [Firebase endpoints did not answer an anonymous request](https://shipreadyai.dev/learn/findings/o15-firebase-ok.md): The database and storage endpoints refused a request that carried no sign in. - [Anyone can create an account](https://shipreadyai.dev/learn/findings/o16-signup-open.md): The public auth settings at {endpoint} report that self signup is on, so a script can create accounts at will. - [New accounts are confirmed automatically](https://shipreadyai.dev/learn/findings/o16-email-confirmation-info.md): The public auth settings report that new sign ups are confirmed automatically, so an account can be created with an address the person does not own. You did not declare customer data, so this is recorded rather than raised. - [Anonymous sign in is turned on](https://shipreadyai.dev/learn/findings/o16-anonymous-signin.md): The public auth settings at {endpoint} report anonymous sign in is on, so a caller can hold a session without ever giving an address. That is fine when it is deliberate and a problem when row rules assume a known person. - [New accounts are active before the address is confirmed](https://shipreadyai.dev/learn/findings/o16-email-confirmation-off.md): The public auth settings report that new sign ups are confirmed automatically, so an account can be created with an address the person does not own. - [Sign in methods published by the backend](https://shipreadyai.dev/learn/findings/o16-auth-settings.md): The public auth settings list these sign in methods: {providers}. - [The auth settings read as expected](https://shipreadyai.dev/learn/findings/o16-auth-ok.md): Self signup is closed and new accounts have to confirm their address. ## Not verified explained - [What we cannot see, and say so](https://shipreadyai.dev/learn/verify.md): The nine items no check of a public address can verify. - [Rollback and recovery](https://shipreadyai.dev/learn/verify/rollback.md): Whether you can put the previous version back, and how long that takes. - [Error monitoring](https://shipreadyai.dev/learn/verify/error-monitoring.md): Whether a failure in production reaches a human rather than sitting in a log nobody opens. - [Sign in and account flows](https://shipreadyai.dev/learn/verify/auth-flows.md): Whether sign in, password or code reset, and session expiry behave under real use. - [Rate limiting and abuse controls](https://shipreadyai.dev/learn/verify/rate-limiting.md): Whether a script can hammer your forms, sign up loop, or paid endpoints without being slowed down. - [Key rotation](https://shipreadyai.dev/learn/verify/secret-rotation.md): Whether you can replace a leaked key quickly and know everywhere it is used. - [Payment handling](https://shipreadyai.dev/learn/verify/payments.md): Whether payment events are verified, replay safe, and matched to the right customer record. - [Customer data handling](https://shipreadyai.dev/learn/verify/customer-data.md): Whether stored personal details are limited, deletable on request, and out of your logs. - [AI feature controls](https://shipreadyai.dev/learn/verify/ai-features.md): Whether prompts, spend, and model output are bounded so one visitor cannot run up the bill. - [Database row rules](https://shipreadyai.dev/learn/verify/backend-rules.md): Whether the row rules behind the app actually stop one signed in account reading another's rows. - [Certificate expiry date](https://shipreadyai.dev/learn/verify/certificate-expiry.md): Whether the certificate is close to expiring. A normal request proves the certificate is valid right now, and the runtime this check uses cannot read the expiry date from that request. - [One account reading another account's data](https://shipreadyai.dev/learn/verify/cross-user-access.md): Whether a signed in account can reach another account's records by changing an id. ShipReady does not create accounts, sign in, or call your functions, so this cannot be answered from outside. ## Launch failure library - [Launch failure library](https://shipreadyai.dev/incidents.md): 16 documented incidents in apps built with AI tools, each with its sources. - [First-quarter 2026 assessment of 200 apps](https://shipreadyai.dev/incidents/first-quarter-2026-assessment.md): 2026-04. 183 of 200 vibe-coded apps, 91.5 percent, contained at least one vulnerability traceable to AI hallucination or missing security context. - [CVE growth in AI-generated code](https://shipreadyai.dev/incidents/cve-growth-2026.md): 2026-03. CVE entries attributed to AI-generated code rose from 6 in January 2026 to more than 35 in March 2026. - [Mercor supply-chain breach](https://shipreadyai.dev/incidents/mercor-supply-chain-breach.md): 2026-03. A 10 billion dollar AI startup was breached through the LiteLLM supply-chain attack, with 4 TB claimed stolen. - [OpenClaw CVE-2026-31992](https://shipreadyai.dev/incidents/openclaw-cve-2026-31992.md): 2026-03. An allowlist bypass scored 9.9 on CVSS and was described as a full guardrail bypass. - [Claude Code data destruction](https://shipreadyai.dev/incidents/claude-code-data-destruction.md): 2026-02. An agent destroyed 2.5 years of production data. - [5,600 vibe-coded apps scanned](https://shipreadyai.dev/incidents/five-thousand-six-hundred-apps-scanned.md): 2026-02. More than 2,000 vulnerabilities and more than 400 exposed secrets found across vibe-coded apps. - [Slopsquatting campaign on npm](https://shipreadyai.dev/incidents/slopsquatting-npm-campaign.md): 2026-02. 126 malicious npm packages exploited AI-hallucinated package names. - [Tenzai study of AI-built apps](https://shipreadyai.dev/incidents/tenzai-study.md): 2026-02. 69 vulnerabilities across 15 apps built by five AI coding tools. - [Gemini CLI project loss](https://shipreadyai.dev/incidents/gemini-cli-project-loss.md): 2026-01. An agent destroyed an entire project by looping a move command to a directory that did not exist. - [Moltbook records exposure](https://shipreadyai.dev/incidents/moltbook-records-exposure.md): 2026-01. An app exposed 4.75 million records, including 1.5 million API tokens and 35,000 email addresses. - [Amazon internal agent outage](https://shipreadyai.dev/incidents/amazon-internal-agent-outage.md): 2025-12. An AI agent deleted and recreated an environment, causing a 13-hour outage. - [Replit agent database deletion](https://shipreadyai.dev/incidents/replit-agent-database-deletion.md): 2025-07. An AI agent wiped production databases while explicitly instructed not to. - [Tea app, first breach](https://shipreadyai.dev/incidents/tea-app-first-breach.md): 2025-07. An unprotected storage instance exposed tens of thousands of user images, including identity documents. - [Tea app, second breach](https://shipreadyai.dev/incidents/tea-app-second-breach.md): 2025-07. Three days after the first breach, over a million private messages were exposed through an API endpoint with no access control. - [Lovable-built apps, CVE-2025-48757](https://shipreadyai.dev/incidents/lovable-cve-2025-48757.md): 2025-05. Broken access control reported across 170 production applications built with Lovable. - [Base44 authentication flaw](https://shipreadyai.dev/incidents/base44-auth-flaw.md): 2025-01. A platform-wide authentication flaw allowed access to private enterprise data. ## Builders - [Builders](https://shipreadyai.dev/builders.md): What each AI builder handles for you, and what it leaves to you. - [Base44](https://shipreadyai.dev/builders/base44.md): Base44 builds and hosts the whole app. When the platform has a flaw, every app on it inherits it. - [Bolt](https://shipreadyai.dev/builders/bolt.md): Bolt gets an app running fast. Speed is the point. Review is still yours. - [Claude Code](https://shipreadyai.dev/builders/claude-code.md): Claude Code works in the terminal with real reach. Guardrails matter more here, not less. - [Codex](https://shipreadyai.dev/builders/codex.md): Codex takes a task and reports what it touched. Keep the task small and the report honest. - [Cursor](https://shipreadyai.dev/builders/cursor.md): Cursor edits your repository. Nothing ships until you ship it, and that is the difference. - [Firebase Studio](https://shipreadyai.dev/builders/firebase-studio.md): Firebase gives you storage and data in one step. The rules are the whole game. - [Lovable](https://shipreadyai.dev/builders/lovable.md): Lovable ships a hosted app with a backend behind it. It handles transport and hosting. It does not decide who may read a row. - [Replit](https://shipreadyai.dev/builders/replit.md): Replit runs the whole workspace, including the agent. That is the power and the risk. - [v0](https://shipreadyai.dev/builders/v0.md): v0 writes the interface. The server boundary is the part to watch. - [Windsurf](https://shipreadyai.dev/builders/windsurf.md): Windsurf keeps the agent close to your editor. The review habit is still the product. ## Stacks - [Launch checklist generator](https://shipreadyai.dev/checklist.md): A seven-answer deterministic checklist for an app's builder, backend, payments, auth, data, AI features, and hosting. - [Lovable plus Supabase plus Stripe launch checklist](https://shipreadyai.dev/checklist/lovable-supabase-stripe.md): A deterministic stack-specific launch checklist. - [Lovable plus Supabase plus None launch checklist](https://shipreadyai.dev/checklist/lovable-supabase-none.md): A deterministic stack-specific launch checklist. - [Lovable plus Lovable Cloud plus Stripe launch checklist](https://shipreadyai.dev/checklist/lovable-lovable-cloud-stripe.md): A deterministic stack-specific launch checklist. - [Lovable plus Lovable Cloud plus None launch checklist](https://shipreadyai.dev/checklist/lovable-lovable-cloud-none.md): A deterministic stack-specific launch checklist. - [Lovable plus Firebase plus Stripe launch checklist](https://shipreadyai.dev/checklist/lovable-firebase-stripe.md): A deterministic stack-specific launch checklist. - [Lovable plus Firebase plus None launch checklist](https://shipreadyai.dev/checklist/lovable-firebase-none.md): A deterministic stack-specific launch checklist. - [Bolt plus Supabase plus Stripe launch checklist](https://shipreadyai.dev/checklist/bolt-supabase-stripe.md): A deterministic stack-specific launch checklist. - [Bolt plus Supabase plus None launch checklist](https://shipreadyai.dev/checklist/bolt-supabase-none.md): A deterministic stack-specific launch checklist. - [Bolt plus Lovable Cloud plus Stripe launch checklist](https://shipreadyai.dev/checklist/bolt-lovable-cloud-stripe.md): A deterministic stack-specific launch checklist. - [Bolt plus Lovable Cloud plus None launch checklist](https://shipreadyai.dev/checklist/bolt-lovable-cloud-none.md): A deterministic stack-specific launch checklist. - [Bolt plus Firebase plus Stripe launch checklist](https://shipreadyai.dev/checklist/bolt-firebase-stripe.md): A deterministic stack-specific launch checklist. - [Bolt plus Firebase plus None launch checklist](https://shipreadyai.dev/checklist/bolt-firebase-none.md): A deterministic stack-specific launch checklist. - [v0 plus Supabase plus Stripe launch checklist](https://shipreadyai.dev/checklist/v0-supabase-stripe.md): A deterministic stack-specific launch checklist. - [v0 plus Supabase plus None launch checklist](https://shipreadyai.dev/checklist/v0-supabase-none.md): A deterministic stack-specific launch checklist. - [v0 plus Lovable Cloud plus Stripe launch checklist](https://shipreadyai.dev/checklist/v0-lovable-cloud-stripe.md): A deterministic stack-specific launch checklist. - [v0 plus Lovable Cloud plus None launch checklist](https://shipreadyai.dev/checklist/v0-lovable-cloud-none.md): A deterministic stack-specific launch checklist. - [v0 plus Firebase plus Stripe launch checklist](https://shipreadyai.dev/checklist/v0-firebase-stripe.md): A deterministic stack-specific launch checklist. - [v0 plus Firebase plus None launch checklist](https://shipreadyai.dev/checklist/v0-firebase-none.md): A deterministic stack-specific launch checklist. - [Cursor or Claude Code plus Supabase plus Stripe launch checklist](https://shipreadyai.dev/checklist/cursor-claude-code-supabase-stripe.md): A deterministic stack-specific launch checklist. - [Cursor or Claude Code plus Supabase plus None launch checklist](https://shipreadyai.dev/checklist/cursor-claude-code-supabase-none.md): A deterministic stack-specific launch checklist. - [Cursor or Claude Code plus Lovable Cloud plus Stripe launch checklist](https://shipreadyai.dev/checklist/cursor-claude-code-lovable-cloud-stripe.md): A deterministic stack-specific launch checklist. - [Cursor or Claude Code plus Lovable Cloud plus None launch checklist](https://shipreadyai.dev/checklist/cursor-claude-code-lovable-cloud-none.md): A deterministic stack-specific launch checklist. - [Cursor or Claude Code plus Firebase plus Stripe launch checklist](https://shipreadyai.dev/checklist/cursor-claude-code-firebase-stripe.md): A deterministic stack-specific launch checklist. - [Cursor or Claude Code plus Firebase plus None launch checklist](https://shipreadyai.dev/checklist/cursor-claude-code-firebase-none.md): A deterministic stack-specific launch checklist. - [Replit launch checklist](https://shipreadyai.dev/stack-launch-checklist/replit.md): A deterministic pre-launch checklist for Replit, focused on workspace secrets, public processes, and deployment settings. - [Next.js launch checklist](https://shipreadyai.dev/stack-launch-checklist/nextjs.md): A deterministic pre-launch checklist for Next.js, focused on server and client boundaries, route handlers, and environment values. - [Remix launch checklist](https://shipreadyai.dev/stack-launch-checklist/remix.md): A deterministic pre-launch checklist for Remix, focused on loaders, actions, sessions, and response headers. - [Astro launch checklist](https://shipreadyai.dev/stack-launch-checklist/astro.md): A deterministic pre-launch checklist for Astro, focused on islands, server endpoints, and deployed adapter behavior. - [Vite launch checklist](https://shipreadyai.dev/stack-launch-checklist/vite.md): A deterministic pre-launch checklist for Vite, focused on client bundles, exposed environment values, and fallback routes. - [Lovable Cloud launch checklist](https://shipreadyai.dev/stack-launch-checklist/lovable-cloud.md): A deterministic pre-launch checklist for Lovable Cloud, focused on row access rules, server actions, and authentication. - [Supabase launch checklist](https://shipreadyai.dev/stack-launch-checklist/supabase.md): A deterministic pre-launch checklist for Supabase, focused on row access rules, grants, functions, and authentication. - [Firebase launch checklist](https://shipreadyai.dev/stack-launch-checklist/firebase.md): A deterministic pre-launch checklist for Firebase, focused on rules, callable functions, and client configuration. - [Convex launch checklist](https://shipreadyai.dev/stack-launch-checklist/convex.md): A deterministic pre-launch checklist for Convex, focused on function exposure, identity checks, and argument validation. - [Custom Node backend launch checklist](https://shipreadyai.dev/stack-launch-checklist/custom-node.md): A deterministic pre-launch checklist for Custom Node backend, focused on request validation, authorization, and production process behavior. - [Custom Python backend launch checklist](https://shipreadyai.dev/stack-launch-checklist/custom-python.md): A deterministic pre-launch checklist for Custom Python backend, focused on request validation, authorization, and production process behavior. - [Stripe launch checklist](https://shipreadyai.dev/stack-launch-checklist/stripe.md): A deterministic pre-launch checklist for Stripe, focused on checkout outcomes, webhook signatures, retries, and refunds. - [Lemon Squeezy launch checklist](https://shipreadyai.dev/stack-launch-checklist/lemon-squeezy.md): A deterministic pre-launch checklist for Lemon Squeezy, focused on checkout outcomes, webhook signatures, and entitlement changes. - [Paddle launch checklist](https://shipreadyai.dev/stack-launch-checklist/paddle.md): A deterministic pre-launch checklist for Paddle, focused on checkout outcomes, webhook signatures, and entitlement changes. - [PostHog launch checklist](https://shipreadyai.dev/stack-launch-checklist/posthog.md): A deterministic pre-launch checklist for PostHog, focused on consent, identity boundaries, and event quality. - [Resend launch checklist](https://shipreadyai.dev/stack-launch-checklist/resend.md): A deterministic pre-launch checklist for Resend, focused on domain setup, failed delivery, and honest interface feedback. - [Clerk launch checklist](https://shipreadyai.dev/stack-launch-checklist/clerk.md): A deterministic pre-launch checklist for Clerk, focused on session validation, protected actions, and sign-out behavior. - [Kinde launch checklist](https://shipreadyai.dev/stack-launch-checklist/kinde.md): A deterministic pre-launch checklist for Kinde, focused on session validation, protected actions, and sign-out behavior. - [Vercel launch checklist](https://shipreadyai.dev/stack-launch-checklist/vercel.md): A deterministic pre-launch checklist for Vercel, focused on environment separation, caching, redirects, and rollback. ## Compare - [Compare](https://shipreadyai.dev/compare.md): Honest comparisons with ten other ways to check an AI-built app. - [ShipReady vs Aikido](https://shipreadyai.dev/compare/aikido.md): A code, cloud and runtime platform for engineering teams that connects to private development systems. - [ShipReady vs CheckVibe](https://shipreadyai.dev/compare/checkvibe.md): A broad scanner with open basic findings and account features for saved and exported reports. - [ShipReady vs LaunchGuard](https://shipreadyai.dev/compare/launchguard.md): A scanner that probes database functions and cross-account access from outside the app. - [ShipReady vs Lovable's built-in scan](https://shipreadyai.dev/compare/lovable-security-scan.md): A project-aware scan inside the Lovable editor that can read internal configuration ShipReady cannot see from outside. - [ShipReady vs Reeve](https://shipreadyai.dev/compare/reeve.md): A research-led scanner that has published a large-scale sweep of AI-built apps. - [ShipReady vs Safe Vibe Codes](https://shipreadyai.dev/compare/safe-vibe-codes.md): A community-facing site with guidance and checks aimed at people shipping AI-built apps. - [ShipReady vs SiteSecurityScore](https://shipreadyai.dev/compare/site-security-score.md): A site-security grader that gives a URL a single score based on outside signals. - [ShipReady vs Vibe App Scanner](https://shipreadyai.dev/compare/vibe-app-scanner.md): A scanner for AI-built apps with broad automated coverage and paid access to the full report. - [ShipReady vs VibeEval](https://shipreadyai.dev/compare/vibeeval.md): A live-URL black-box scanner whose findings are reviewed by an engineer before delivery. - [ShipReady vs VibeShip Scanner](https://shipreadyai.dev/compare/vibeship-scanner.md): A free open-source scanner that checks public repositories and returns AI-oriented fix guidance. ## Glossary - [Glossary](https://shipreadyai.dev/glossary.md): 44 terms from a Launch Risk Check result, in plain English. - [Anon key](https://shipreadyai.dev/glossary/anon-key.md): The public browser key. Safe to publish, useless without rules behind it. - [Batch prompt](https://shipreadyai.dev/glossary/batch-prompt.md): One instruction that fixes several findings in a single pass. - [Claim token](https://shipreadyai.dev/glossary/claim-token.md): The unguessable string that lets you attach an anonymous result to your account later. - [Content-Security-Policy](https://shipreadyai.dev/glossary/content-security-policy.md): The header that tells the browser which code it is allowed to run. - [Cookie flags](https://shipreadyai.dev/glossary/cookie-flags.md): The three settings that decide how safely a cookie travels. - [Cost cap](https://shipreadyai.dev/glossary/cost-cap.md): The ceiling that stops one visitor spending your month's budget in an hour. - [Could not check](https://shipreadyai.dev/glossary/could-not-check.md): The request failed, so there is no result for that item. - [Cross origin rules](https://shipreadyai.dev/glossary/cross-origin-rules.md): The header that decides which other sites may read your responses. - [Declared](https://shipreadyai.dev/glossary/declared.md): Something you told us, recorded as your statement rather than our finding. - [Detected](https://shipreadyai.dev/glossary/detected.md): Something the check worked out about your app without being told. - [DMARC](https://shipreadyai.dev/glossary/dmarc.md): The record that tells receiving servers what to do when mail fails your checks. - [Domain expiry](https://shipreadyai.dev/glossary/domain-expiry.md): The date your domain registration runs out, published in the registry. - [Entitlement](https://shipreadyai.dev/glossary/entitlement.md): The record that says this account paid for this thing. - [Evidence](https://shipreadyai.dev/glossary/evidence.md): The line of raw observation behind a finding. - [Exposed path](https://shipreadyai.dev/glossary/exposed-path.md): An address that answers when it should not. - [Fingerprint](https://shipreadyai.dev/glossary/fingerprint.md): What your app quietly tells the internet about how it was built. - [Fix prompt](https://shipreadyai.dev/glossary/fix-prompt.md): A ready instruction for the tool that built your app. - [frame-ancestors](https://shipreadyai.dev/glossary/frame-ancestors.md): The rule that stops another site putting your app inside an invisible frame. - [Hardening Sprint](https://shipreadyai.dev/glossary/hardening-sprint.md): The $1,750 engagement that takes the top items from needs fix to fixed and re-verified. - [HSTS](https://shipreadyai.dev/glossary/hsts.md): The header that tells browsers to never speak to your site over plain HTTP again. - [Idempotency](https://shipreadyai.dev/glossary/idempotency.md): Doing the same thing twice has the same effect as doing it once. - [Launch Review](https://shipreadyai.dev/glossary/launch-review.md): The $199 review where a named person looks at what a URL cannot see. - [Launch Risk Statement](https://shipreadyai.dev/glossary/launch-risk-statement.md): A dated page saying what was observed, what was declared, and what nobody verified. - [Mixed content](https://shipreadyai.dev/glossary/mixed-content.md): A secure page loading something over plain HTTP. - [Not verified](https://shipreadyai.dev/glossary/not-verified.md): Named items nobody checked, listed rather than quietly dropped. - [Observed](https://shipreadyai.dev/glossary/observed.md): Something a check actually read from your published app, with the evidence attached. - [Open signup](https://shipreadyai.dev/glossary/open-signup.md): Whether anyone can create an account, and whether the address has to be proved. - [Prompt injection](https://shipreadyai.dev/glossary/prompt-injection.md): Text your app feeds to a model that the model treats as instructions. - [Publishable key](https://shipreadyai.dev/glossary/publishable-key.md): The newer name for a public client key. Same rule: public by design, not a permission. - [Rate limit](https://shipreadyai.dev/glossary/rate-limit.md): The rule that slows down whoever is asking too often. - [Release Assurance](https://shipreadyai.dev/glossary/release-assurance.md): The monthly option that keeps a current statement for teams shipping every week. - [Release Gate](https://shipreadyai.dev/glossary/release-gate.md): The $49 package that hands you the checklist and the guardrails to fix things yourself. - [Rollback](https://shipreadyai.dev/glossary/rollback.md): Putting the previous version back, quickly, when the new one is wrong. - [Row level security](https://shipreadyai.dev/glossary/row-level-security.md): The rule that decides which rows of a table an account may read or change. - [Security definer](https://shipreadyai.dev/glossary/security-definer.md): A database function that runs with its author's permissions rather than the caller's. - [Service role key](https://shipreadyai.dev/glossary/service-role-key.md): The key that ignores every access rule. It belongs on a server and nowhere else. - [Slopsquatting](https://shipreadyai.dev/glossary/slopsquatting.md): Registering the package names AI tools invent, and waiting. - [Source map](https://shipreadyai.dev/glossary/source-map.md): The file that turns your shipped bundle back into readable source. - [SPF](https://shipreadyai.dev/glossary/spf.md): The DNS record naming who is allowed to send email as your domain. - [Staleness](https://shipreadyai.dev/glossary/staleness.md): How out of date an observation is, stated rather than hidden. - [Storage bucket](https://shipreadyai.dev/glossary/storage-bucket.md): The place uploaded files live, and the setting that decides who can read them. - [Tenant isolation](https://shipreadyai.dev/glossary/tenant-isolation.md): One customer's data staying entirely out of another customer's account. - [Trust Center](https://shipreadyai.dev/glossary/trust-center.md): A published page that answers the security questions buyers ask. - [Webhook signature](https://shipreadyai.dev/glossary/webhook-signature.md): Proof that the message really came from the service that claims to have sent it. ## Report and blog - [State of launch readiness](https://shipreadyai.dev/report/state-of-launch-readiness.md): Aggregate numbers from completed Launch Risk Checks: the share with each observed issue by builder and backend, the median scan time, and the most common could not check causes. Publishes at 100 completed checks. - [Blog](https://shipreadyai.dev/blog.md): Writing on launching AI-built apps, drawn from the documented incidents. - [The Launch Ledger, 2026](https://shipreadyai.dev/blog/the-launch-ledger-2026.md): A month by month series through 2026: each documented incident or study, what an outside check would have observed, and what it could not have seen. ## Policies - [Privacy policy](https://shipreadyai.dev/legal/privacy.md): What ShipReady collects when you run a Launch Risk Check or buy a product, how long it is kept, and how to have it deleted. - [Terms of service](https://shipreadyai.dev/legal/terms.md): The agreement between you and ShipReady covering the free Launch Risk Check, the paid products, authorization to test, and the limits of what our findings mean. - [Refund policy](https://shipreadyai.dev/legal/refunds.md): Release Gate refunds within 7 days, Launch Review refunds any time before work starts, and Hardening Sprint refunds any time before scope confirmation. - [Cookie policy](https://shipreadyai.dev/legal/cookies.md): Every cookie and browser storage item ShipReady sets, by name, purpose, provider and lifetime, and how to change your analytics choice. ## For agents - [For AI agents](https://shipreadyai.dev/agents.md): Plain text and markdown versions of everything ShipReady publishes, for AI agents and crawlers that prefer reading text. - [Launch Risk Check skill](https://shipreadyai.dev/skills/shipready-launch-risk-check/SKILL.md): How an agent runs a check, reads the three lists, and describes the result honestly. - [Release Gate skill](https://shipreadyai.dev/skills/shipready-release-gate/SKILL.md): How an agent installs and runs the Release Gate for a customer who owns it. - [AGENTS.md snippet](https://shipreadyai.dev/agents/AGENTS.md): Paste into your own repository so your coding agent knows when to run a check. - [CLAUDE.md snippet](https://shipreadyai.dev/agents/CLAUDE.md): The same snippet in the form Claude Code reads. - [MCP endpoint](https://shipreadyai.dev/mcp): Four tools, described in the connect section of the agents page. - [Free tools index](https://shipreadyai.dev/tools/llms.txt): Every page under /tools. - [Findings explained index](https://shipreadyai.dev/learn/findings/llms.txt): Every page under /learn/findings. - [Not verified explained index](https://shipreadyai.dev/learn/verify/llms.txt): Every page under /learn/verify. - [Launch failure library index](https://shipreadyai.dev/incidents/llms.txt): Every page under /incidents. - [Builders index](https://shipreadyai.dev/builders/llms.txt): Every page under /builders. - [Stacks and checklists index](https://shipreadyai.dev/checklist/llms.txt): Every page under /checklist. - [Compare index](https://shipreadyai.dev/compare/llms.txt): Every page under /compare. - [Glossary index](https://shipreadyai.dev/glossary/llms.txt): Every page under /glossary. - [Report and blog index](https://shipreadyai.dev/blog/llms.txt): Every page under /blog. - [security.txt](https://shipreadyai.dev/.well-known/security.txt): How to report a problem. - [humans.txt](https://shipreadyai.dev/humans.txt): Who builds this. - [Sitemap](https://shipreadyai.dev/sitemap.xml): Every indexable address. - [Trust Center](https://shipreadyai.dev/.well-known/trust.html): Platform trust evidence for ShipReady, published by TechTide AI. - [Contact](mailto:Alex@techtideai.io): Alex@techtideai.io ## Optional - [llms-full.txt](https://shipreadyai.dev/llms-full.txt): Every documentation page concatenated into one file. Per-page markdown replaces it for most uses, and is the faster way to read one topic.