Checks across the surface your users can reach.
Paste a public URL and LaunchLock reviews headers, TLS, cookies, exposed files, client-side secrets, DNS posture, observed APIs, and bounded abuse-control signals.
One scan, the whole launch surface.
Every scan covers security, SEO, and AEO lanes at once, and the report is honest about what ran, what was skipped, and what failed.
Security headers
Every discovered route
Exposed files & source maps
Public artifacts flagged
DNS & email posture
SPF, DMARC, CAA
Client dependency review
Known-vulnerable libraries
Headers, TLS & cookies
Reviews security headers, TLS configuration, cookie flags, and CORS behavior on the routes your visitors actually reach.
Exposed files & source maps
Flags publicly reachable files, source maps, and build artifacts that reveal more of your app than you intended to ship.
Client-side secrets & storage
Looks for keys and tokens embedded in shipped JavaScript and reviews what your app keeps in browser storage.
DNS & email posture
Checks SPF, DMARC, and CAA records so your domain’s email and certificate posture is launch-ready.
Bounded by default
Quick uses strict request, concurrency, and time limits while checking the public surface and observed login/API protections.
Three scan depths
Quick is the anonymous, passive-by-default hook. Standard is a paid API/MCP profile. Deep is the Pro/Max project workflow; normal active access requires verification and consent.
See the score your app would get today
The free Quick scan uses a bounded budget and shows your lane counts plus one real issue teaser. The report clearly lists what ran and what could not be reached.