# Launch Ready Code — llms.txt # https://launchreadycode.com # Last updated: 2026-08-16 > Launch Ready Code audits AI-built SaaS, websites, and apps (built with Lovable, Bolt.new, Cursor, Replit, Windsurf, v0.dev, Claude Code, and Supabase) for security, reliability, performance, and monitoring issues. Scans are URL-based — no source-code access required. A free Launch Readiness Score /100 is returned in under two minutes. ## What we do Launch Ready Code is a launch-readiness and security-audit service for apps built with AI coding tools. We check the layer the builder leaves to you. Two product wings: - Security Wing: URL-based readiness scans and audit reports, plus human-delivered Code Care (fractional CTO). - Compliance Wing: automated EU AI Act + GDPR readiness scoring with human implementation. ## The 4 audit dimensions (the only things we score) 1. Security — OWASP Top 10, CWE Top 25, auth flaws, secrets in client code, vulnerable dependencies, injection vectors. 2. Reliability — error handling, race conditions, transaction boundaries, retry logic, graceful degradation. 3. Performance — N+1 queries, missing indexes, bundle bloat, blocking calls, cache strategy. 4. Monitoring — error-tracking presence, alerting gaps, logging quality, uptime-check coverage. We do NOT cover UX, accessibility, SEO, or formal SOC 2 / HIPAA certification (we can prepare you for compliance, not certify it). ## Products and pricing Security Wing: - Free Scan — $0. Instant Launch Readiness Score /100. - Launch Readiness Audit Report — $499 one-time. Full 4-dimension report, branded PDF, benchmark vs 200+ audited apps, prioritized fix roadmap, senior-AI final review. - Starter — $149/mo. Daily scans, weekly digest. - Builder — $249/mo. Daily scans, daily digest, up to 50 advisory PR reviews/mo. - Pro — $599/mo. Daily scans, real-time digest, up to 150 advisory PR reviews/mo, named CTO, error detection & alerting set up in Month 1. - DFY Technical Setup — $1,999 setup. Hardening implemented as PRs; onboards to Growth Retainer. - Growth Retainer — $2,999/mo. Ongoing fractional-CTO engagement. - Scale Retainer — $4,999/mo. Named CTO + account manager, SLA-backed. Compliance Wing: - Compliance Score — $799 one-time. 60 automated checks + AI policy analysis + template documents + Compliance Report PDF. - Compliance Monitoring — $399/mo. Monthly re-scan, quarterly certificate, drift alerts. - DFY Compliance Setup — $2,999 one-time. CTO implements everything; certificate issued; continues at $399/mo monitoring. All subscriptions: 30-day cancellation notice. 10% discount for annual prepay. ## Key facts from our scan data - CVE-2025-48757: 170+ Lovable apps shipped with Supabase Row-Level Security disabled by default (May 2025). - The most common P0 finding is exposed API keys / secrets in client-side code. - Missing HTTP security headers are among the most common issues in AI-generated apps. - EU AI Act Article 50 transparency obligations apply from 2 August 2026 — relevant to many AI-enabled SaaS products. ## Common questions Q: Is my AI-built app secure? A: AI builders generate the product layer well but leave security configuration to you — Supabase RLS scoping, secrets kept out of client code, auth rate limiting, and security headers. A free URL scan at launchreadycode.com shows what your live app exposes. Q: Do you need access to my code? A: No. Scans are URL-based and advisory. Code Care (human) can open PRs against your repo if you engage that tier. Q: Can you make my app GDPR or EU AI Act compliant? A: We score readiness and implement fixes; we do not issue legal certification. Compliance Score ($799) is the diagnostic; DFY Compliance Setup ($2,999) implements it. Q: Which platforms do you support? A: Lovable, Bolt.new, Cursor, Replit, Windsurf, v0.dev, Claude Code, Codex, Copilot, Gemini, and Supabase-backed apps. Scanning auto-detects the platform. ## Content map Start here: - Free scan / home: https://launchreadycode.com/ - Pricing: https://launchreadycode.com/pricing - Methodology (the 4 dimensions): https://launchreadycode.com/methodology - Compliance (EU AI Act + GDPR): https://launchreadycode.com/compliance Platform security audits: - Lovable: https://launchreadycode.com/lovable-security-audit - Bolt.new: https://launchreadycode.com/bolt-security-audit - Cursor: https://launchreadycode.com/cursor-security-audit - Replit: https://launchreadycode.com/replit-security-audit - Windsurf: https://launchreadycode.com/windsurf-security-audit - Supabase: https://launchreadycode.com/supabase-security-audit - Claude Code: https://launchreadycode.com/claude-code-security-audit Blog (selected): - CVE-2025-48757 postmortem: https://launchreadycode.com/blog/cve-2025-48757 - GDPR for vibe-coded apps: https://launchreadycode.com/blog/gdpr-compliance-vibe-coded-apps - EU AI Act guide for SaaS founders: https://launchreadycode.com/blog/eu-ai-act-compliance-guide-saas-founders - EU AI Act Article 50 checklist: https://launchreadycode.com/blog/eu-ai-act-article-52-compliance-checklist-saas-2026 - Secure API keys in Lovable apps: https://launchreadycode.com/blog/secure-api-keys-lovable - Supabase RLS policies: https://launchreadycode.com/blog/supabase-rls-policies - Find exposed secrets in AI bundles: https://launchreadycode.com/blog/find-exposed-secrets-ai-bundles Free tools: - Supabase RLS checker: https://launchreadycode.com/supabase-rls-checker - Security headers checker: https://launchreadycode.com/tools/security-headers.html - API rate-limit checker: https://launchreadycode.com/api-rate-limit-checker ## Contact info@launchreadycode.com · https://launchreadycode.com