Pricing

A $15K pentest, self-serve, in plain English.

Point ShipShape at an app you own. It safely probes for the real vulnerabilities attackers use (XSS, broken access control, exposed secrets) plus the AI-specific holes that ZAP, Burp, and Snyk were never built to test, like LLM prompt injection. You get a plain-English report, exact fixes, a downloadable report (HTML today, PDF on the roadmap), and a “Scanned by ShipShape” badge. Launch pricing below.

What is live today: ShipShape runs the Free-tier scan now, with four live probes (XSS, broken access control, exposed secrets, prompt injection), ownership verification, a plain-English report, downloadable report and findings files, and a “Scanned by ShipShape” badge. Features tagged Planned describe the Pro and Team launch roadmap and are not built yet.

Free

$0

Launch pricing. No card required.

Solo builders who want to see one real scan before they trust it.

  • One full scan per month on one verified app
  • Four web checks: reflected XSS, broken access control / IDOR, exposed secrets, missing security headers
  • Two AI-specific checks: LLM prompt injection and LLM data disclosure
  • Plain-English report with severity and a fix for every finding
  • Ownership verification so you can only scan apps you control
  • Findings stay in your account, not sold or shared
Run my free scan
Most popular

Pro

$49/ month

Launch pricing. Billed monthly. Cancel anytime.

Indie founders with real users and a security questionnaire on their desk.

  • Unlimited scans on up to 5 verified appsPlanned
  • Expanded web and AI coverage as new probes ship (model and data exposure, unsafe AI output handling)Planned
  • Scheduled scans, daily or weekly, on autopilotPlanned
  • Diffing: get alerted only when a new vulnerability appears since your last clean scanPlanned
  • Downloadable PDF report you can hand to a customer or auditorPlanned
  • “Scanned by ShipShape” badge with a live verification linkPlanned
  • Email and Slack alerts on new findingsPlanned
Start Pro

Team

$199/ month

Launch pricing. Billed monthly. Includes 3 seats.

Small teams shipping AI features fast, with no security hire yet.

  • Everything in Pro, on up to 20 verified appsPlanned
  • 3 seats included, add more at $29 per seat per monthPlanned
  • Scan API and CI/CD hooks to fail a build on new critical findingsPlanned
  • Shared workspace with roles, so the whole team sees the same findingsPlanned
  • Webhook alerts and exportable JSON for your own dashboardsPlanned
  • Scan history and trend reporting for questionnaire and audit evidencePlanned
  • Priority supportPlanned
Start Team
How we compare

The pros use Burp and ZAP. You shipped the app.

The old tools are powerful. They are also priced for pen testers, built for security engineers, and none of them probe your LLM out of the box. Here is the honest lay of the land.

CapabilityShipShapeOWASP ZAPBurp SuiteSnyk
PriceFree, then $49–$199/moDemo scan is free, no cardFreeOpen source$499/user/yrEnterprise from ~$18K/yr$25/dev/moEnterprise ~$15K–$40K/yr
Built forThe person who shipped the appSecurity engineersProfessional pen testersDev teams (code + deps)
Scans your live app (DAST)YesYesYesNoScans your code, not the running app
Tests the AI holes (prompt injection, LLM leaks)YesNot by defaultNot by defaultNot by default
Plain-English report with a fix per findingYesNoRaw outputFor expertsDev-focused
Setup and expertise neededLowHost one verification file on your siteHighHighDev integration

ZAP and Burp are deeper tools built for security professionals, and ShipShape is not trying to out-muscle them. It is built for the person who shipped the app and needs real answers in plain English, including the AI holes none of these three probe by default. Dedicated AI-security tools do exist; ShipShape's angle is combining both in one report for a non-specialist. Pricing reflects public 2026 figures; enterprise tiers are quote-based, so those are ranges.

ShipShape is not a replacement for a human penetration test. It automates the classes of vulnerability it knows how to test, and it tests them well. It does not do the lateral, creative work a skilled human tester does. If you need a signed pentest for compliance, use ShipShape to find and fix the obvious holes first, then bring in a human for the rest.