ShipSafe logo
Security Code Scanning · Privacy Security

ShipSafe

ShipSafe runs AI-orchestrated security audits on websites and REST APIs, firing 38+ active exploit tests across the OWASP Top 10 and returning plain-English fixes. A passive quick scan is free; a full audit costs a single $29 payment.

Active Free plan Freemium No public API Verified by Guidaio
Overview

What is ShipSafe?

ShipSafe is an automated security auditing service for websites and REST APIs, built for people who ship software without a security specialist on hand. Its pitch is a direct comparison: a traditional penetration test runs to $10,000 and takes two to four weeks, while ShipSafe orchestrates the same class of industry-standard tooling and returns an answer in minutes.

Under the hood it drives OWASP ZAP, Nmap, Nikto, Playwright and SSLyze against the target. Nmap handles port and service discovery, ZAP injects payloads into live endpoints, and SSLyze verifies the certificate chain and cipher suites. Altogether the platform advertises more than 38 active exploit tests spanning the OWASP Top 10, security headers, TLS configuration, infrastructure and API surface. Google Gemini 2.5 Pro then reads the raw output and rewrites it as something a founder can act on, with step-by-step fixes rather than a dense engineering appendix.

The product comes in two tiers. The free Quick Scan is passive and read-only, finishes in two to five minutes, and returns a score out of 100 plus a count of issues by severity, with a single low-severity finding unlocked and a 90-day retention window. The $29 Deep Audit is the real product: full active exploit testing, plain-English remediation steps, a PDF export, a shareable report link and a permanent archive. It is a one-time payment per report, with no subscription, and no domain verification or DNS configuration is required, so any URL can be scanned immediately.

That last convenience carries the product's sharpest condition. Because Deep Audits perform genuine active exploit testing, the terms require you to own the target or hold explicit written permission, and warn that infrastructure providers may read the traffic as an attack. Make Real LLC, the studio behind the tool, disclaims responsibility for downtime, account suspensions or legal consequences arising from unauthorized testing, and states plainly that an audit does not guarantee an application is secure.

The intended audience is explicit throughout: vibe coders, AI app builders, SaaS founders, agency owners and solo developers who need to answer have you been pen-tested? with something real.

What it does

  • Run 38+ active exploit tests against a website or REST API, covering the OWASP Top 10
  • Discover open ports and running services with Nmap
  • Inject payloads into live endpoints with OWASP ZAP to confirm exploitable flaws
  • Check TLS/SSL configuration and certificate chains with SSLyze
  • Score the target out of 100 and rank every finding by severity
  • Turn raw tool output into plain-English remediation steps with Google Gemini 2.5 Pro
  • Export the audit as a PDF or share it through a permanent report link
Audience

When to use ShipSafe / When not to

A quick filter to help you decide if ShipSafe is the right fit.

When to use ShipSafe

  • Solo developers and vibe coders shipping AI-assisted apps without a security background
  • SaaS founders facing a security questionnaire from an enterprise prospect
  • Freelancers and agency owners who audit client sites before launch
  • Small teams that need an audit-ready report without hiring a penetration testing firm
  • Non-technical product owners who need vulnerabilities explained in plain language

When not to use ShipSafe

  • Anyone wanting to scan a target they neither own nor have written permission to test
  • Security teams needing continuous monitoring rather than a one-off, per-report audit
  • Organizations that require a signed DPA, a formal subprocessor list or SOC 2 evidence
  • Teams auditing native mobile binaries or source code, which fall outside the tool's scope
  • Companies that cannot allow intrusive exploit tests against production infrastructure
Get started

How to use ShipSafe

A typical end-to-end flow, from setup to results.

  1. Confirm you own the target URL or hold written permission to test it - the terms require it
  2. Create an account at the sign-up page, where authentication is handled by Clerk
  3. Enter the URL of the website or REST API you want audited
  4. Launch the free Quick Scan and wait two to five minutes for the passive pass to finish
  5. Read the score out of 100 and the breakdown of issues by severity
  6. Open the single low-severity finding that the free tier unlocks
  7. Pay the one-time $29 through Stripe to unlock the Deep Audit
  8. Let the 38+ active exploit tests run across the OWASP Top 10
  9. Work through the plain-English remediation steps attached to each finding
  10. Export the report as a PDF or send the shareable link to a prospect or an auditor
Quick read

Pros & Cons

Pros

  • $29 per audit against the $10,000+ the site quotes for a traditional penetration test
  • Results in minutes rather than the two to four weeks a manual engagement takes
  • One-time payment, with no subscription and no enterprise sales cycle
  • Findings written for developers and founders, with concrete remediation steps
  • A permanent free tier lets you see what is exposed before paying anything
  • The underlying scanners are named and well known, so the coverage can be checked
  • PDF and shareable link make the report usable in a sales cycle or a compliance review

Cons

  • The vendor states outright that an audit does not guarantee a secure application and should not be your only line of defense
  • Refunds are generally refused once a scan completes, except on the vendor's own technical failure
  • Active exploit testing can trigger downtime or account suspension at the target's host, at your risk
  • The free Quick Scan unlocks only one low-severity finding and purges reports after 90 days
  • No public API, no mobile app, no browser extension and no continuous monitoring
  • No DPA, no contractual subprocessor list and no SOC 2 or ISO certification published
  • Thin publisher transparency: no postal address, no incorporation date, and legal documents dated May 2024 while the domain was registered in February 2026
Pricing

Pricing & Plans

ShipSafe operates a permanent free tier. The Quick Scan is available at no cost. The lowest paid entry point is the ShipSafe Deep Audit at USD 29.00, charged as a single one-time payment per report rather than as a recurring subscription, and processed through Stripe.

Quick Scan - Free
  • passive
  • read-only scan
  • security score and issue count by severity
  • one low-severity finding unlocked
  • 90-day report retention
ShipSafe Deep Audit - $29, one time
  • full active exploit testing
  • 38+ checks across the OWASP Top 10
  • plain-English remediation steps
  • PDF report export
  • shareable report link
  • permanent report archive
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how ShipSafe handles your data.

GDPR overview

Implementation is minimal and purely declarative. The privacy policy names the GDPR once, alongside the CCPA, to say that users may - depending on their location - hold rights of access, rectification and erasure, and it routes those requests to support@makereal.app. That is the full extent of it. ShipSafe never states in so many words that it is GDPR compliant, so no compliance claim can fairly be attributed to it. There is no designated Article 27 EU representative, no named data protection officer, no data processing agreement, no standard contractual clauses, no legal bases set out per purpose and no declared hosting jurisdiction. The policy carries a Last updated: May 20, 2024 stamp, which predates the domain itself and points to a template that has not been revisited.

Who owns the data?

Nothing in the terms transfers ownership of your reports to the vendor: Make Real LLC positions itself as a processor of what you submit. The privacy policy splits the data three ways. Account details go through Clerk, which handles your name, email address and profile picture. Scan data covers the target URL, the raw findings from the security tools and the AI interpretations built on top of them. Billing data is handled by Stripe, and card details never reach ShipSafe's own servers. Technical findings travel to Google Gemini 2.5 Pro for interpretation, explicitly stripped of account information, while the scanning workers run on isolated cloud instances. You can delete your account and every associated record from the dashboard at any time.

Reuse rights

Nothing in the terms restricts what you do with a report once it is yours. ShipSafe actively encourages reuse: paid audits ship with a PDF export, a shareable report link and a permanent archive, and the product is pitched around handing those results to enterprise prospects and compliance reviewers. No licence is granted or withheld in writing, which in practice means you may republish, forward or attach the report without asking. The vendor reserves a parallel right over the same material: the privacy policy states that collected data feeds the improvement of its security testing algorithms and AI interpretations.

Data retention & training

Retention summary
Retention depends on which tier produced the report. Free Quick Scans are kept for 90 days and then purged automatically. Paid Deep Audits and the reports attached to them are archived permanently inside your account and stay there until you choose to delete them. Deletion is self-service: the privacy policy states you can remove your account and all associated data from the dashboard at any time. Beyond that, the policy says nothing about how long account records or billing data are held once the account is gone, and it makes no mention of anonymization or of any retention period applied to the technical findings shared with third-party providers.
Trains on customer data
Unclear
Subprocessors disclosed
Yes
GDPR contact

Hosting summary

ShipSafe declares almost nothing about where data lives. The privacy policy says only that its security workers run on isolated cloud instances, naming no provider, no country and no region. Neither the policy nor the terms identify a hosting jurisdiction, and the terms sidestep governing law as well, deferring to whichever jurisdiction Make Real LLC is registered in without naming it. What is named is the set of third parties that touch the data along the way: Clerk for authentication, Stripe for payments and Google Gemini for interpreting the findings. Separately, and outside anything the vendor declares, the domain resolves to 216.198.79.1, an anycast address geolocated in the United States on Amazon's AS16509. That is a technical observation about where the marketing site is served, not a statement about where scan data or reports are stored, and it should not be read as one.

Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting ShipSafe.

  • A good score can breed false confidence: the vendor explicitly guarantees nothing about your application's security
  • Active exploit testing is intrusive and may cause downtime or get your account suspended by your own host
  • Scanning a target without written authorization is your legal exposure alone, not the vendor's
  • Automated checks miss business logic and design flaws, so they cannot replace human review
  • Paid reports catalogue exploitable vulnerabilities and are archived permanently on the vendor's side
  • Technical findings are transmitted to a third party, Google Gemini, for interpretation
  • Waving a scan report as commercial proof overstates it: the document carries no certification value
Setup

Setup & Integrations

Technical difficulty

Essentially none. There is nothing to install, no agent to deploy and no code to add to your application, and ShipSafe requires neither domain verification nor DNS configuration. You create an account through Clerk, paste a URL and start a scan. Reports are written for people without a security background. The only real prerequisite is not technical but legal: you must own the target or hold explicit written permission to test it, and satisfying that condition can take longer than the scan itself.

Deployment

Web app

Supported languages

English
Company

Behind ShipSafe

Company name
Make Real LLC
Founded
INFORMATION_NOT_FOUND
Country of origin
🇺🇸 United States
UBO
Mahbub Rahman
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Legal contact
Support contact
Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What exactly does ShipSafe do?
It actively tests a website or REST API for more than 38 vulnerabilities, covering the OWASP Top 10 as well as infrastructure, headers and TLS configuration, using tools such as OWASP ZAP, Nmap, Nikto and Playwright. Google Gemini 2.5 Pro then turns the raw output into a plain-English report with exact fixes.
Is ShipSafe a monthly subscription?
No. The Deep Audit is a one-time $29 payment per report, so you pay only when you actually need an audit. The Quick Scan tier stays free permanently.
Do I have to verify my domain first?
No. Both the Quick Scan and the Deep Audit run on any URL immediately, with no DNS configuration involved.
Can I scan a site I do not own?
No. The terms require you to own the target or hold explicit written permission to test it. Make Real LLC declines responsibility for downtime, account suspensions or legal consequences arising from unauthorized testing.
What does the free Quick Scan actually give me?
A passive, read-only pass completed in two to five minutes, returning a score out of 100 and a count of issues by severity, with one low-severity finding unlocked. Those reports are purged automatically after 90 days.
How long are my reports kept?
Free Quick Scans are retained for 90 days and then purged automatically. Paid Deep Audits and their reports are archived permanently in your account unless you delete them, and you can remove your account and all associated data from the dashboard at any time.
Which third parties handle my data?
Clerk for authentication, Stripe for payment processing and Google Gemini for interpreting the technical findings. The scanning workers themselves run on isolated cloud instances. ShipSafe states that personal account information is not sent to the AI models.
Can I get a refund?
Generally not once a scan has completed successfully, because the compute and AI costs are already incurred. If a scan fails through a technical error on ShipSafe's side, support will issue a credit or a refund.
Who is behind ShipSafe?
It is a product of Make Real LLC, a small development studio. The single published contact address, covering support, legal and privacy matters alike, is support@makereal.app.
Is there a mobile app or a public API?
Neither was found. ShipSafe is a web application; it scans REST APIs but does not expose one of its own.
Conclusion

Should you pick ShipSafe?

ShipSafe answers a real and specific problem: the gap between shipping an application and being able to prove it is not trivially exploitable. For a founder who assembled a product with AI assistance, or an agency about to hand a site to a client, the traditional answer - a five-figure penetration test booked weeks ahead - is out of all proportion. Running OWASP ZAP, Nmap, Nikto and SSLyze under an AI layer that rewrites the output in plain language is a sensible way to close that gap, and the $29 one-time price removes most reasons to postpone it.

What it is not is a substitute for a security program, and to its credit the vendor says so: the terms disclaim any guarantee that an application is secure and describe automated testing as one component among others. Two things deserve care before you run it. First, Deep Audits perform genuine active exploit testing, so you must own the target or hold written permission, and your host may read the traffic as an attack - the consequences of getting that wrong sit entirely with you. Second, the report is a diagnostic, not a certification: sharing it with an enterprise prospect is legitimate, presenting it as an accredited audit is not.

The weakest part of the offering is publisher transparency rather than the product itself. Make Real LLC publishes no postal address, no incorporation date, no certification and no data processing agreement, and its privacy policy and terms are stamped May 2024 while the domain was only registered in February 2026. For a $29 diagnostic that is a reasonable trade. For anyone whose procurement process demands contractual guarantees on data handling, it is the point where ShipSafe stops being the right tool.