Company

About Launchioo

We help teams ship safer code on GitHub with automated pull request checks that fit the workflow you already have.

Our mission

Launchioo helps development teams catch security issues in pull requests before they merge. We believe PR security should be automatic, deterministic, and native to GitHub — not another tool to babysit or a black-box AI guess.

Every merged pull request is a ship event. We built Launchioo so secrets, SSRF, CSRF gaps, injection sinks, and multi-step exploit chains get flagged on the PR itself, where developers are already paying attention.

What we do

Launchioo is a GitHub App that scans added and changed lines in pull request diffs with 50+ deterministic rules across 8 modules. When something looks wrong, we post a PR comment, optional inline review comments, and a GitHub check run with pass, warn, or fail policy (Pro enables merge-blocking fail checks; Free stays advisory).

Our engine covers categories including:

  • Secrets & credentialsEntropy-aware detection with false-positive control for emails and placeholders.
  • SSRF engineURL classification, internal IP blocking, and redirect-chain awareness.
  • CSRF & auth bypassState-changing requests, cookie flags, and weak authorization patterns.
  • Exploit chain detection across your codebaseLightweight source → transform → sink tracking with graph-based chain detection.
  • Network & redirectsCleartext HTTP/WS detection with auth-context severity escalation.
  • Supply chain & dependenciespackage.json and CI install pattern analysis.
  • Injection & XSSClassic dangerous patterns on every added diff line.
  • Context-aware severityRule severity adjusted by execution context — not one-size-fits-all.

Each scan reports a security score (0–100), risk index, severity breakdown, and attack paths when taint or exploit chains are detected. Results sync to your dashboard for history and trends (Free: last 10 scans; Pro: full history and analytics).

Free and Pro

Free includes full rule detection on 5 PR scans and 1 full repository audit per month (UTC), one connected repository, and advisory check outcomes — you see every finding without merge blocking.

Pro unlocks unlimited scans and repositories, red fail checks for branch protection, full exploit-chain depth, security debt tracking, repository rankings, security goals, advanced dashboard analytics, and Executive PDF reports. See pricing for the full comparison.

How we work with GitHub

We integrate through official GitHub APIs — OAuth for sign-in and a GitHub App for repository access. We read pull request metadata and diffs needed to run scans, post comments, and update check runs. We do not require your GitHub password, and you control which repositories the app can access at install time.

Learn more in our setup guide.

Who it's for

Launchioo is built for software teams shipping on GitHub — startups, agencies, and engineering orgs that want lightweight, automated security guardrails without standing up a full static-analysis pipeline on day one.

We are not a replacement for a comprehensive security programme or professional penetration testing. We are an always-on first line of defence at the pull-request boundary.

Get in touch

Questions, feedback, or partnership enquiries? We would love to hear from you.