[free] [open-source] [MIT]

Security standards
in 30 seconds

Drop production-grade security policies into any repository. Audit your codebase. Guide your AI agents to write safer code.

~/my-saas-app
$
the-problem

// AI writes your code.
// Who writes your security?

AI coding agents ship features fast — but they skip input validation, leak secrets in logs, miss auth checks, and ignore rate limiting. Without explicit rules, they don't know what “secure” means for your project.

Hardcoded API keys that reach production
Missing authentication on internal routes
No rate limiting on login or payment endpoints
Error responses that leak stack traces
Database queries without row-level security

ShipSecure gives your AI agent the rules it needs to avoid these mistakes.

built-for

$ Built for

If you ship software, this is for you.

// Solo developers

Shipping a SaaS, side project, or freelance app and want production-grade security without hiring a consultant.

// AI-first teams

Using Cursor, Claude, Copilot, or other AI agents and need guardrails so generated code follows your security policies.

// Startup engineers

Moving fast with a small team and need a security baseline before your first customer, audit, or SOC 2.

// Open source maintainers

Want contributors to follow security standards without writing a 50-page guide from scratch.

// Fullstack developers

Building with Next.js, Supabase, Firebase, or similar stacks and need stack-specific security patterns.

// Teams preparing for compliance

Need documented security policies for SOC 2, HIPAA, or investor due diligence — fast.

why-shipsecure

$ Why ShipSecure?

Built for developers who ship fast and need to ship safe.

Security Score

Get a score out of 100 for your repo. See exactly what's missing and what to fix before you ship.

Secret Scanning

Catches hardcoded API keys, database credentials, and service tokens before they hit production.

AI-Ready Templates

Every template has "MUST FOLLOW" rules your AI agent reads and enforces while writing code.

Zero Config

One command. No accounts. No dependencies. No config files. Works in any repo, any stack.

ai-agents

$ Works with your AI agent

Don't use the terminal? Just tell your AI coding agent what to do. It runs the command, reads the output, and fixes the issues.

CursorClaude CodeWindsurfCopilotAny AI agent
AI Agent Prompt
Run npx secure-repo audit in my project and fix all the security issues it finds. Then run npx secure-repo init to add the missing policies.
commands
$ npx secure-repo audit
Scan your repo for security issues
$ npx secure-repo init
Add free security templates
$ npx secure-repo init --key <key>
Add free + pro templates
$ npx secure-repo upgrade
See what's in the pro pack
$ npx secure-repo check
Check if templates are outdated
$ npx secure-repo list
Show all available templates

Six commands.
Zero config.

Everything runs from your terminal. No accounts. No config files. No dependencies. Just npx and go.

how-it-works

$ How it works

Three steps. Under 30 seconds.

1

Audit

Scan your repo for missing policies, exposed secrets, and security gaps.

$ npx secure-repo audit
2

See your score

Get a score out of 100 with clear, actionable issues to fix.

Security Score: 100 / 100
3

Fix it

Drop in production-grade templates. Your AI agent follows them automatically.

$ npx secure-repo init
pro-pack
[pro-pack]

Complete security coverage

30 files. One command. Everything you need to ship secure software.

$19
One-time purchase. Yours forever.
free-templates

Free (4 files)

SECURITY.md

No secrets in code. Privileged keys server-side only. Database access control. Incident response steps.

AUTH.md

JWT verification. Token storage. Password hashing. Rate limiting on login. Session revocation.

API.md

Input validation on every endpoint. Rate limiting. Error responses that don't leak internals. CORS.

ACCESSIBILITY.md

WCAG 2.1 AA compliance. Semantic HTML. Keyboard navigation. Screen reader support. Color contrast.

pro-pack-details

Pro (+27 files)

18 policy templates

Database, deployment, incident response, payments, data privacy, file uploads, rate limiting, access control

100+ point audit

Complete production security audit with severity ratings and explanations

Stack presets

Supabase (6 files) and Firebase (3 files) with platform-specific rules

Code examples

Next.js route handlers, rate limiting, Zod validation, RLS policies

FreePro
Security audit
Core policies (4)
Engineering standards (18)
Audit checklist
Stack presets
Code examples (5)
get-started

$ Ship secure software today

Start free. Upgrade when you need complete coverage.

sponsor

Sponsor ShipSecure

Help keep this project free and maintained. Your support funds new templates, features, and stack presets.

Become a sponsor