🚢 Pre-launch security scanner

Is your app shipshape?

You built something brilliant. Now make sure it's ready for the open water. Seaworthy scans your project for security gaps, misconfigurations, and exposed secrets before you hit deploy.

Runs from your terminal, VS Code, or your AI coding agent (Claude Code, Cursor, Windsurf).

✓
🧭 About Seaworthy

Built for builders who move fast

You're a vibe coder. You ship on intuition and iteration. Seaworthy is your first mate — a quick pre-launch scan that catches the stuff you didn't think to check: leaked API keys, missing security headers, exposed secrets, and misconfigurations that could bite you after you go live. Everything runs locally on your machine. For LLM-assisted checks you bring your own API key — we never touch your code or bill you for AI usage.

Now your AI agent can run the scan too. Nearly half of AI-generated code ships with security vulnerabilities, and most developers say they don't fully trust AI output — Seaworthy's MCP server puts a pre-deploy security check inside your agent's loop, so you can ship what it builds with confidence.

💻 Broad Support

Supported Languages

Seaworthy analyzes code across 13 major programming languages, frameworks, and configuration syntaxes. We support full taint tracking for runtime environments and static AST checks for markup, styles, and configs.

⚡ Runtime & Backend (Full Taint Tracking)

🟦
TypeScript
.ts
🟨
JavaScript
.js, .jsx
⚛️
TSX
.tsx
🐍
Python
.py
🐹
Go
.go
🐘
PHP
.php
💎
Ruby
.rb, .rake, .gemspec, Gemfile, Rakefile, config.ru
☕
Java
.java
🦀
Rust
.rs
🐚
Bash / Shell
.sh, .bash, .zsh

📁 Configuration & Static (AST Scanning)

🌐
HTML
.html
🎨
CSS
.css
🗄️
SQL
.sql, .pgsql, .psql
🐳
Docker
Dockerfile, Dockerfile.*
📋
JSON
.json
📝
YAML
.yaml, .yml
🔍 The Full Sweep

What we check

Seaworthy runs a suite of automated checks — no manual steps, no config files needed.

🔒Free + Pro

Security

Hardcoded secrets, committed .env files, missing auth, permissive CORS, SQL injection surfaces, and sensitive data appearing in logs.

🛡️Pro

Resilience

Rate limiting gaps, missing input validation, unhandled errors, missing pagination, no HTTP timeouts, and absent retry logic on critical calls.

⚙️Free + Pro

Ops Basics

Missing health check, hardcoded localhost URLs, debug mode left on, unstructured logging, and no graceful shutdown handling.

📦Free

Dependency Hygiene

Known CVEs in dependencies, missing or outdated lockfile, dev dependencies bundled into production, and floating version pins.

🔧Free + Pro

Configuration

Secrets hardcoded in source files, no separation of environment configs, and default credentials left unchanged.

👁️Pro

Data Exposure

Verbose error messages leaking internals, PII returned in API responses, and no response filtering on list endpoints.

🗺️ Simple as sailing

Three steps to clear skies

⚡
1

Run the scan

One command, zero config. npx seaworthycode [path] — scans your project locally and privately. Or just ask your AI agent to run it.

📋
2

Review findings

Categorised, severity-ranked report in your terminal, browser, or editor. Clear, prioritised, no noise.

🚀
3

Ship with confidence

Fix the gaps before they reach production. Know your app is seaworthy before you deploy.

🤖 Built for agents

Your agent writes the code. Seaworthy checks it.

Seaworthy ships a built-in MCP (Model Context Protocol) server, so your AI coding agent can run a security scan without leaving its loop. Everything runs locally — only license authentication ever touches our servers.

🔌
1

Agent calls scan

Your agent invokes the scan tool on the directory it's working in — no terminal, no context switch.

📋
2

Reads the findings

Compact, prioritised findings land straight in the agent's context: leaked secrets, missing auth, insecure patterns.

🔁
3

Fixes and re-scans

The agent fixes the code and re-scans until it's clean — security becomes part of the loop, not an afterthought.

Works with the agents you already use

Claude CodeCursorWindsurfClaude DesktopVS Code

Add Seaworthy to your MCP config

{ "mcpServers": { "seaworthy": { "command": "npx", "args": ["-y", "seaworthycode", "mcp"] } } }

Learn more about the MCP server →

💳 Simple Pricing

Pick your plan

Start free. Upgrade when you need the full picture.

Every plan includes: CLI · VS Code extension · MCP server

Free

£0forever
  • ✓Core security checks (~12)
  • ✓Unlimited projects
  • ✓Secrets & CVE detection
  • ✓No account needed
Get started free
Most popular

Pro

£2.99/ month
  • ✓Full check catalog + BYOK LLM*
  • ✓Unlimited projects
  • ✓Auth, rate limits & resilience
  • ✓HTML + JSON reports

* LLM checks run using your own agent with your key.

🌊⚓

Ready to set sail? 🌊

Run your first scan free. Drop it in your terminal or install the VS Code extension — no account needed.

💻 CLI (npx)

$ npx seaworthycode

Runs in any project directory. No install needed.

🔌 VS Code Extension

Scan from inside your editor, with inline findings.

Install Extension

🤖 AI Agents (MCP)

{ "mcpServers": { "seaworthy": { "command": "npx", "args": ["-y", "seaworthycode", "mcp"] } } }

Let Claude Code, Cursor, or any MCP client run the scan for you.

MCP setup guide →