Pricing

A $15K pentest, self-serve, in plain English.

Point ShipShape at an app you own. It safely probes for the real vulnerabilities attackers use (XSS, broken access control, exposed secrets) plus the AI-specific holes that ZAP, Burp, and Snyk were never built to test, like LLM prompt injection. You get a plain-English report, exact fixes, a downloadable report (HTML today, PDF on the roadmap), and a “Scanned by ShipShape” badge. Launch pricing below.

What is live today: ShipShape tests thirteen classes — nine in the instant check that needs no setup (missing security headers, no HTTPS, insecure cookie flags, mixed content, version disclosure, exposed secrets including those in your JavaScript bundle, config files like .env served publicly, and whether your Supabase or Firebase database answers strangers) and four more once you verify you control the site (reflected XSS, broken access control / IDOR, LLM prompt injection, LLM data disclosure). Accounts, monthly monitoring, the scan record, the questionnaire packet and the fix pack are built. Anything tagged Planned is not.

Not switched on yet: payments and email delivery. Nothing can be purchased and no report can be posted to you until they are. The product says so at the point you would otherwise be waiting.

Free

$0

No card. No trial clock.

Anyone who wants to know what a stranger can already see.

  • Instant check on any site: nine classes, no signup
  • Reads your JavaScript bundle, its code-split chunks and any source map
  • Checks whether your Supabase or Firebase database answers strangers
  • Full deep scan on one site you verify — XSS, access control, prompt injection, LLM leaks
  • Every finding in full, with its location and a fix. Nothing is blurred
  • Downloadable report and machine-readable findings file
Run a free scan
Most popular

Pro

$49/ month

Billed monthly. Cancel from Stripe's own portal, any time.

A founder with real users and a security questionnaire on their desk.

  • Everything in Free, on one verified site
  • Monthly re-scan with an emailed report, even when nothing changed
  • Change tracking: what appeared, what you fixed, what is still open
  • Scan record you can send to whoever asked — dated, printable, with its own reference
  • Security questionnaire responses, filled in from your actual scan
  • Fix pack: a prompt per finding to paste into Cursor or Claude, and a re-scan to prove it
  • Posture trend against your own previous months
  • Slack and Discord alerts on a new findingPlanned

Team

$199/ month

Billed monthly. Includes 3 seats.

A small team shipping AI features with no security hire yet.

  • Everything in Pro, on up to 10 verified sites
  • Scan history and trend reporting across every site
  • 3 seats includedPlanned
  • Scan API and CI/CD hooks to fail a build on a new criticalPlanned
  • Shared workspace with rolesPlanned
  • Webhooks and exportable JSON for your own dashboardsPlanned
  • Priority supportPlanned

Enterprise

Let's talk

Quoted per deal. Annual, invoiced.

Agencies and platforms running security across a portfolio of sites.

  • Site packs: 20, 50, 100 or more, priced per pack
  • Everything in Team across every site in the pack
  • Named contact and an agreed response timePlanned
  • Single sign-onPlanned
  • Audit logPlanned
  • Custom data retentionPlanned
  • White-labelled reports for your own clientsPlanned
Talk to us
How we compare

The pros use Burp and ZAP. You shipped the app.

The old tools are powerful, priced for pen testers, and built for security engineers. None of them checks whether your database answers strangers, and none probes your LLM out of the box. Here is the honest lay of the land.

CapabilityShipShapeOWASP ZAPBurp SuiteSnyk
PriceFree, then $49–$199/moFree scan, no cardFreeOpen source$499/user/yrEnterprise from ~$18K/yr$25/dev/moEnterprise ~$15K–$40K/yr
Built forThe person who shipped the appSecurity engineersProfessional pen testersDev teams (code + deps)
Checks your database is not readable by strangersYesSupabase RLS and Firebase rulesNoNoNo
Reads your JavaScript bundle for leaked keysYesIncluding code-split chunks and source mapsNot by defaultNot by defaultScans your repo, not the shipped bundle
Tests the AI holes (prompt injection, LLM leaks)YesNot by defaultNot by defaultNot by default
Says what it could NOT testYesUntested never reads as a passRaw outputFor expertsDev-focused
Setup and expertise neededLowPaste a URL. Host one file for the deep scanHighHighDev integration

ZAP and Burp are deeper tools built for security professionals, and ShipShape is not trying to out-muscle them. Dedicated AI-security tools exist too. ShipShape's angle is the stack a solo founder actually ships on — a bundle, a backend-as-a-service database, and an LLM — at a price that does not need a sales call. Pricing reflects public 2026 figures; enterprise tiers are quote-based across this whole category.

ShipShape is not a replacement for a human penetration test. It automates the classes of vulnerability it knows how to test, and it tells you which ones it could not run. It does not do the lateral, creative work a skilled human tester does. If you need a signed pentest for compliance, use ShipShape to clear the obvious holes first, then bring in a human for the rest.