Is your code
safe to ship?
Safeship is a security co-pilot for people who build with AI. Connect a GitHub repo and we'll scan it for leaked secrets, insecure code, and vulnerable dependencies — then explain every finding in plain English, ranked by real-world risk, with a copy-paste fix.
Free · open-source engines · no credit card
Hardcoded API key committed to config.ts
What it means
A secret key is committed to your repository — anyone who can read the code can use it to access your service. Rotate the key and load it from an environment variable instead.
- const key = "sk_live_9f2c8a1b…"; + const key = process.env.API_KEY;
Three ways your code leaks risk
Every scan runs three trusted, open-source engines — so nothing common slips through.
Leaked secrets
API keys, tokens, and passwords accidentally committed to your repo.
Vulnerable dependencies
Known CVEs in the open-source packages your project depends on.
Insecure code
SQL injection, unsafe eval, weak crypto, and other risky patterns.
Powered by Gitleaks · Semgrep · OSV
From repo to fixes in minutes
No config, no agents to install, nothing to learn.
- 1
Connect
Sign in with GitHub and pick any repository — public or private.
- 2
Scan
Safeship runs trusted engines over your code in a temporary sandbox.
- 3
Fix
Get findings ranked by real-world risk, each with a plain-English fix — or open a pull request in one click.
An AI security co-pilot
Beyond finding issues, Safeship helps you understand and fix them.
Advisor
AI reviews your database schema, tech stack, and optimizations — and draws your tables and relationships so you can see what to fix.
Assistant
Ask about any finding or your code and get clear, streaming answers — no security jargon required.
One-click fixes
Turn a finding into a reviewed pull request on a new branch. You approve every change.
Bring your own model
Prefer GPT-4o or Claude? Plug in your own API key — the same model everywhere, or a different one per feature.
It only ever reads — never attacks
Security tooling you can point at your own code without worry.
- Static analysis only — no port scans, no live traffic, no exploitation.
- Your code is scanned in a temporary sandbox and never stored.
- Secrets are redacted before anything is sent to the AI.
- It only writes through pull requests you review and merge.
Questions, answered
Is it really free?
Yes — open-source engines and free infrastructure, no paid API and no credit card. Prefer a premium model? You can plug in your own API key.
Do you store my code?
No. Your repo is scanned in a temporary sandbox and discarded — nothing is kept. Secrets are redacted before anything reaches the AI.
What can it scan?
Any GitHub repository you can access, public or private, across most popular languages — for leaked secrets, vulnerable dependencies, and insecure code.
Will it change my code?
Only if you ask. Fixes open as pull requests on a new branch for you to review — Safeship never pushes to your main branch.
Ready to see what's in your code?
Connect a repository and get your first security report in a couple of minutes. It's free.