Every finding is free.
All 39 checks run on every plan, including the free trial, and every finding is shown in full with its fix. We do not hold a security problem back to sell you something. What you pay for is how often we look, how much history we keep, and the verified checks that need your permission.
Free
Free
Three scans. Every check, every finding, every fix — nothing held back.
- All checks — the full set, not a subset
- Every finding in full, with its fix
- 3 scans, ever
- Reports readable for 24 hours
- Google sign-in, no card
Watch
$7/mo
or $70/year — two months free
One app, watched every week. You get told when something changes.
- 20 scans a month
- 1 app monitored weekly
- Email alert on anything new
- Full scan history kept
- Unlimited fix re-checks
Pro
Most chosen$19/mo
or $190/year — two months free
Five apps, checked every day and on every deploy, confirmed against your backend.
- Unlimited scans
- 5 apps, checked daily and on every deploy
- Verified deep checks — row-level security, storage, records, exposed files
- Instant alerts on anything new
- Public trust page and embeddable badge
- Printable report
- 2 team seats
First 25 customers keep this price permanently. It rises afterwards — the lock is the offer, not a discount.
Agency
$49/mo
or $490/year — two months free
For people who ship other people’s websites and get asked whether they are safe.
- Everything in Pro
- 25 apps
- White-label reports with your own name and logo
- API access with your own keys
- Slack and Discord alerts
- 5 team seats
What is actually different
| Free | Watch | Pro | Agency | |
|---|---|---|---|---|
| All checks, every finding, every fix | Yes | Yes | Yes | Yes |
| Scans | 3, ever | 20 / month | Unlimited | Unlimited |
| Report kept for | 24 hours | Forever | Forever | Forever |
| Apps monitored | — | 1 | 5 | 25 |
| How often we check | — | Weekly | Daily + every deploy | Daily + every deploy |
| Verified deep checks | — | — | Yes | Yes |
| Email alerts | — | On anything new | Instant | Instant |
| Fix re-checks | Uses a scan | Unlimited | Unlimited | Unlimited |
| History and regression timeline | — | Full | Full | Full |
| Public trust page and badge | — | — | Yes | Yes |
| Printable report | — | — | Yes | White-labelled |
| Slack / Discord alerts | — | — | — | Yes |
| API access | — | — | — | Yes |
| Team seats | 1 | 1 | 2 | 5 |
- All checks, every finding, every fix
- FreeYesWatchYesProYesAgencyYes
- Scans
- Free3, everWatch20 / monthProUnlimitedAgencyUnlimited
- Report kept for
- Free24 hoursWatchForeverProForeverAgencyForever
- Apps monitored
- Free—Watch1Pro5Agency25
- How often we check
- Free—WatchWeeklyProDaily + every deployAgencyDaily + every deploy
- Verified deep checks
- Free—Watch—ProYesAgencyYes
- Email alerts
- Free—WatchOn anything newProInstantAgencyInstant
- Fix re-checks
- FreeUses a scanWatchUnlimitedProUnlimitedAgencyUnlimited
- History and regression timeline
- Free—WatchFullProFullAgencyFull
- Public trust page and badge
- Free—Watch—ProYesAgencyYes
- Printable report
- Free—Watch—ProYesAgencyWhite-labelled
- Slack / Discord alerts
- Free—Watch—Pro—AgencyYes
- API access
- Free—Watch—Pro—AgencyYes
- Team seats
- Free1Watch1Pro2Agency5
Questions
Why is the free tier this generous?
Because withholding a critical finding to force an upgrade is extortion, and in a security product trust is the only asset we have. If we find that your database is open, we tell you, and we tell you how to close it. The paid plans exist because your site will break again next month and you will not be watching.
Why do prices change by country?
$19 is a rounding error in San Francisco and a real decision in Lagos or Dhaka. A single global price either prices out most of the world or leaves money on the table in the richest tenth of it. We read the country your request comes from and discount accordingly, in five bands. A VPN defeats it; everyone who does regional pricing has that problem and accepts it, because the alternative is not doing it at all.
What do the verified checks add?
Certainty. Without permission we can see that a site ships a database key and six table names, but we will not query the database to find out whether those tables are locked down — so the honest answer is “we cannot tell”. Once you verify ownership we ask directly, table by table, and tell you which ones answer.
Do you store any of my users' data?
No, and it is structural rather than a promise. Where a check needs to know whether a table is readable we ask for a row count instead of rows, so the response body is empty. Credentials are reduced to a type and last four characters before anything is stored. The privacy policy is short because there is little to describe.
Do you send attack payloads?
Never. No injection strings, no scripts, no fuzzing, no brute force. We detect indicators — an error signature, an exposed endpoint, a reflected parameter — and we say so. Nothing we do could damage the site we are checking.
I am an agency. Which plan?
Agency. Twenty-five client sites, a monthly report with your own name and logo on it, API access, and five seats. The report is usually the actual deliverable when a client asks whether the thing you built them is safe.
Can I cancel?
Any time, and you keep access to the end of the paid period. If ShipSafe has not been useful, email us within 30 days of a charge and we refund it. No form, no retention call.