Pricing for pre-ship security scans
Pay for focused scans of AI-built apps and agent runtimes before launch. Launch Check is available now for $5 during the launch offer. Deep Ship Review, Launch Bundle, Agent/MCP Deep, and Builder Monthly are Available Soon.
- Security headers audit
- Exposed file checks
- Passive route and metadata mapping
- Browser, cookie, CORS, and platform exposure checks
- VibeCoding pattern detection
- Public AI-agent config signals
- Deep and Agent/MCP checks excluded
- Security headers audit
- Exposed file checks
- Passive route and metadata mapping
- Browser, cookie, CORS, and platform exposure checks
- VibeCoding pattern detection
- Public AI-agent config signals
- Report with severity and fixes
- Everything in Launch Check
- Safe active injection, redirect, and rate-limit probes
- API, GraphQL, webhook, and request-handling checks
- SOC 2 readiness classification and owner-evidence map
- WCAG 2.2 A/AA automated signals plus manual-review checklist
- Premium context-required auth, tenant, upload, and workflow checklist
- Repo, CI/CD, container, cloud, and owner-context audit
- PDF report export
Bundles and advanced tiers
Launch Bundle, Agent/MCP Deep, and Builder Monthly are Available Soon.
Launch Bundle
5 Launch Check credits
Bulk credits are not available for purchase yet.
Agent/MCP Deep
OpenClaw, Hermes, Clawdbot, and MCP runtime posture with tool exposure, sensitive-action, and prompt-injection checks
Agent-runtime checkout is not available yet.
Builder Monthly
10 Launch Checks, 1 Deep Ship Review, history, and retest workflow
Not available for purchase yet
Join Builder waitlistFeature comparison
Current scanner coverage by scan type.
| Feature | Free Signal | Launch Check | Deep Ship Review | Builder Monthly |
|---|---|---|---|---|
| Security headers audit | Planned | |||
| Exposed file checks | Planned | |||
| Passive route and metadata mapping | Planned | |||
| Browser, cookie, CORS, and platform exposure checks | Planned | |||
| VibeCoding pattern detection | Planned | |||
| Public AI-agent config signals | Planned | |||
| Safe active injection, redirect, and rate-limit probes | Planned | |||
| API, GraphQL, webhook, and request-handling checks | Planned | |||
| OpenClaw, Hermes, Clawdbot, and MCP agent runtime posture | Agent/MCP Deep | Planned | ||
| SOC 2 readiness classification and evidence map | Planned | |||
| WCAG 2.2 accessibility signals and review checklist | Planned | |||
| Premium context-required auth and tenant checks | Planned | |||
| Premium repo, CI/CD, container, cloud, and AI-agent context audit | Agent/MCP Deep | Planned | ||
| PDF report export | Planned | |||
| Scans included | 1 launch | 1 per purchase | Available Soon | Available Soon |
Current scope
SOC 2 readiness, WCAG 2.2, and AI-agent/MCP gateway coverage are Deep coverage. Automated findings are reported as signals; owner evidence, tool policies, and manual accessibility review remain context-required unless you provide staging accounts, repo access, platform configuration, and test workflows.Frequently asked questions
What you get when you buy a scan today.
What is a Launch Check vs Deep Ship Review?
A Launch Check covers passive public-surface checks: headers, exposed files, metadata, browser posture, CORS, cookies, and platform exposure. Deep Ship Review adds safe active probes, API checks, SOC 2 readiness classification with a Trust Services Criteria evidence map, WCAG 2.2 accessibility checks, repo/cloud owner-context coverage, and the context-required pentest checklist.
Is this SOC 2 or WCAG certification?
No. VibeCodeGuard reports SOC 2 readiness classification and WCAG 2.2 accessibility signals. SOC 2 attestation requires an independent auditor, and WCAG conformance requires manual accessibility validation across real user workflows.
Is this a full penetration test?
No. VibeCodeGuard is an automated public-surface scanner for pre-ship checks. It can catch common launch issues quickly, but it does not replace a manual security review for high-risk systems.
How do credits work?
Credits are prepaid Launch Check tokens. New accounts include one Launch Check credit, but using that included credit requires a no-charge Stripe registration so the free scan stays limited to one account. Launch Bundle, Deep Ship Review, and Agent/MCP Deep are Available Soon.
Can I get a refund?
If something goes wrong with checkout or scan processing, contact support with the scan or purchase id. Refunds are reviewed case by case and are processed through Stripe when approved.
Is my data safe?
VibeCodeGuard scans only publicly reachable URLs you submit. We store account email, scan target URL, scan status, findings, reports, Stripe customer/payment/setup identifiers, and a hashed Stripe card fingerprint for free-scan abuse prevention. Stripe handles card details.
When will Builder Monthly be available?
Builder Monthly is not available for purchase yet. The waitlist is for teams that want recurring scans, priority workflow, and collaboration features when those are ready.
Focused scope
Public URL scans
Stripe checkout
Card data handled by Stripe
PDF reports
Export completed scans
Run the check before launch
Start with a $9 $5 Launch Check. Deep Ship Review and Agent/MCP Deep are Available Soon.