Straight answers before you scan.
The questions every builder asks before pointing a scanner at their own app. No hedging.
You can only scan apps you prove you control. Before ShipShape runs a single request, you pass an ownership-verification gate: you host a small text file we generate for you at your site's root. No proof of ownership, no scan. This keeps you on the right side of the law, because scanning a site you do not own without permission is illegal, full stop. ShipShape is built so you cannot point it at someone else's app.
No. ShipShape is non-destructive by design. It reads and probes the way a careful tester would, and it avoids payloads that write, delete, or alter your data. It does not run mass fuzzing that hammers your database, and it will not submit destructive actions in your app. Scheduled off-peak scans are a planned Pro feature; for now you run scans on demand, and if you run a fragile production system, start with a staging copy.
Only with your explicit consent. Evidence gathered from your own verified apps (request and response snippets that prove a finding) stays tied to your account and is never sent to any third-party LLM. We do not sell your data. If you opt in, we store anonymized findings (the vulnerability class, not your data) to improve detection, and you can turn that off at any time. Your report is yours to download and delete.
No, and we will not pretend otherwise. ShipShape tests specific, well-defined classes of vulnerability automatically. It is not a certification, and it is not a substitute for a human pentester who thinks laterally and chains bugs together. Just as important: a clean scan is not proof your app is safe. Absence of findings means ShipShape did not find those specific issues, not that none exist. Use it to catch the common, costly holes fast, and to show a customer you take security seriously.
The ones traditional scanners miss because they were built before LLMs shipped in production apps. Today ShipShape actively probes for prompt injection (OWASP's number one LLM risk) and, through those probes, the leaking of system prompts and model configuration. Broader AI coverage (unsafe handling of AI-generated output, wider data-exposure checks) is on the roadmap. If your app has a chatbot, an agent, or any LLM call a user can influence, this is the part ZAP, Burp, and Snyk do not cover.
We tune hard against noise. Every finding comes with the evidence that triggered it (the request and the response) so you can confirm it in seconds instead of arguing with a black box. When ShipShape is not certain, it labels a finding as “worth a look” rather than crying wolf. You will not get a 200-item report where 190 are junk.
ShipShape scans your app over HTTP the way a browser or an attacker does, so it does not care whether you built on Next.js, Rails, Django, FastAPI, Express, or a no-code builder. If it has a public URL and you can verify ownership, ShipShape can scan it. AI checks work against any LLM your app calls, since ShipShape tests your endpoints, not your model vendor.
Most scans finish in minutes, not hours. A small app is often done in under ten minutes. Larger apps with many pages and endpoints take longer, and the AI checks add a little time because they run adversarial prompts one by one. You get progress as it runs, and a full report the moment it finishes.
That is exactly who we built this for. Run a scan, fix what it finds, and download the report as evidence you tested for OWASP and AI-specific issues (an HTML report today, with PDF export on the roadmap). Add the “Scanned by ShipShape” badge to your site so prospects see it before they even ask. It will not replace a SOC 2 report, but it closes the most common questions fast and shows real diligence.
Enter your app's URL, and pass the ownership check by hosting a small file we generate for you. Then run your first scan. The free tier is designed to give you one full scan with no card, so you can see a real report before you pay. Most people go from start to their first finding in minutes.