Coverage

Every check family we run, with the limits shown.

A LaunchLock scan reviews the surface your users can already reach — leaked keys, exposed files, missing headers, invisible pages. Here is the full list of check families, what each one looks for, and how honest coverage reporting works.

Headers & TLS

up to high
  • Security headers on the routes visitors reach (CSP, HSTS, frame and content-type protections)
  • TLS configuration and certificate posture
  • Redirect behavior from HTTP and www variants

Cookies & CORS

up to high
  • Cookie flags: Secure, HttpOnly, SameSite on session cookies
  • CORS behavior and wildcard origins
  • Cross-origin isolation signals

Exposed files & source maps

up to critical
  • Publicly reachable env files, configs, and backups
  • Source maps shipped to production
  • Build artifacts and directory listings that reveal your stack

Client-side secrets & storage

up to critical
  • API keys and tokens embedded in shipped JavaScript
  • Live payment and service keys in the bundle
  • What your app keeps in localStorage and sessionStorage

Auth surface

up to high
  • Login, signup, and password-reset surface discovery
  • Session handling signals visible from the outside
  • Common auth misconfiguration patterns in AI-built apps

DNS & email posture

up to medium
  • SPF, DMARC, and CAA records
  • Domain configuration that affects deliverability and certificates
  • Subdomain posture visible from public DNS

SEO fundamentals

up to medium
  • Indexability: robots.txt, sitemaps, canonical tags, noindex mistakes
  • Metadata, Open Graph, and structured data
  • Pages invisible to search that you meant to ship

AEO reachability

up to low
  • Whether the crawlers behind ChatGPT, Claude, Perplexity, and Gemini can reach your site
  • Answer-engine blocking rules you may not know you have
  • Content signals AI assistants use to cite you

Launch readiness

up to medium
  • Route discovery across the public surface
  • Client dependency review for outdated libraries
  • A scored, honest summary: what ran, what was skipped, what failed
How coverage is reported

No silent passes. Every report states what ran, what was skipped, and what failed.

Bounded by default.

Quick uses strict request, concurrency, and time limits across the public site, observed APIs, and login protection signals.

External adapters fail closed.

When an integration or tool is unavailable, the report says skipped — never silently passed. Deep-scan ZAP and Nuclei coverage stays skipped while guarded external-tool egress is disabled.

Deeper checks stay scoped.

Standard and Deep keep plan, project, rate-limit, scope, and audit controls around their broader checks.

Someone will run these checks on your app. Better it’s you.

The free Quick scan considers every passive family above within a 60-second scan budget — no account, no card, no installs.