BreachProbeONE URL, READ-ONLY
MENU
Scan free1 CRITICAL OPEN
33 issue types32 written fixes30 tables per scan2 throwaway accountsnothing written$19 report · $39 with 30 nightly re-scans

BREACHPROBE / SECURITY SCANNERS FOR VIBE-CODED APPS

LaunchGuard vs Suparbase

The same 6 criteria for both, with the page each figure came from and the day it was read.

SECTIONS

2 compared· 6 criteria, identical for every column· every competitor figure read off that company's own page· last verified 2026-09-18

On what it costs, LaunchGuard is Free · Pro $29/month and Suparbase is Free · Hosted $12 per user/month. On what it needs from you, LaunchGuard is A URL; sign-up to see full key details and Suparbase is A Supabase URL and an API key. On tests as a signed-in user, LaunchGuard is Yes and Suparbase is No — anonymous probe, plus a simulator. On tests one user reading another's rows, LaunchGuard is Yes, as a saved guard and Suparbase is Simulated, one role at a time. On re-checks after you ship, LaunchGuard is Every deploy, on Pro and Suparbase is Yes, on the paid tier. On what you get, LaunchGuard is Findings, the request receipt, and a fix and Suparbase is An admin workspace; the scan is on-screen. BreachProbe publishes this table and is one of the things in it, so read the case for the other side below rather than taking the table's word for it. Every figure was read off the named company's own page on or since 2026-09-18; the URLs and the dates are at the foot of this page, and a job re-fetches each one on a schedule and fails when a figure is no longer on the page it came from.

THE TABLESecurity scanners for vibe-coded apps compared on the same 6 criteria
CRITERIONLAUNCHGUARDSUPARBASE
What it costsFree · Pro $29/month“Free $0 forever … Pro $29 / month”. The free tier is not a findings paywall: “It is not a paywall on findings.”Free · Hosted $12 per user/month“Free $0 forever” covers one solo workspace and “Up to 3 Supabase connections”; “$12 per user / month” adds unlimited connections and Agent Sentry’s continuous scans.
What it needs from youA URL; sign-up to see full key details“Signing up (still free, no card) reveals the full leaked key and the fix prompt.”A Supabase URL and an API key“Paste a Supabase URL + API key”. The key is encrypted at rest and proxied server-side rather than held in the browser. The free Security Scanner is the lighter path — it needs no account.
Tests as a signed-in userYes“Logged-in tests included: we sign in as a real user, not just a stranger”.No — anonymous probe, plus a simulatorThe scanner is explicitly the stranger’s view: “See what a stranger can read from your Supabase project.” Roles are covered separately inside the admin, which can “simulate SELECT/INSERT/UPDATE/DELETE as any role with custom JWT claims. All rolled back.” That is a simulation against your own connection, not a request made by a signed-up account.
Tests one user reading another's rowsYes, as a saved guardThe free tier saves “up to 2 guards … for a cross-user leak, a payment bypass, or any rule you name”.Simulated, one role at a timeThe “RLS debugger” sets custom JWT claims and runs a statement as that role, and the write is “All rolled back.” So one user reading another’s rows is something you construct query by query, rather than a result the tool signs up two accounts to produce.
Re-checks after you shipEvery deploy, on Pro“It re-checks on every deploy, automatically, the moment you ship”.Yes, on the paid tier“Agent Sentry continuous scans” is a Hosted line item, described on the homepage as a “Continuous anon-key probe” with per-AI-agent session attribution and one-click undo.
What you getFindings, the request receipt, and a fix“Every finding, and the receipt: the exact request we sent and what your app sent back”.An admin workspace; the scan is on-screenWhat you buy is a surface you work in — “Row cards, type-aware forms, FK lookups, bulk operations, CSV/JSON in + out, undoable deletes”. The free scanner keeps nothing: “the security scanner is stateless”.

Every figure below was read off that company's own page; each source URL and the date it was read are listed at the foot of this page. BreachProbe is the publisher of this table and is not one of the 2 compared — it scores these rather than competing with them.

TESTS AS A SIGNED-IN USERwhether the tool authenticates and probes as a real account, rather than only reading what an anonymous stranger can reach
TESTS ONE USER READING ANOTHER'S ROWSthe two-account test. It is the only check that can tell a working row-level security policy from one that is merely present
ANSWERS4 questions

LaunchGuard vs Suparbase — what it costs?

LaunchGuard: Free · Pro $29/month. “Free $0 forever … Pro $29 / month”. The free tier is not a findings paywall: “It is not a paywall on findings.”. Suparbase: Free · Hosted $12 per user/month. “Free $0 forever” covers one solo workspace and “Up to 3 Supabase connections”; “$12 per user / month” adds unlimited connections and Agent Sentry’s continuous scans. Read from launchguard.dev and suparbase.com on 2026-09-18.

LaunchGuard vs Suparbase — what it needs from you?

LaunchGuard: A URL; sign-up to see full key details. “Signing up (still free, no card) reveals the full leaked key and the fix prompt.”. Suparbase: A Supabase URL and an API key. “Paste a Supabase URL + API key”. The key is encrypted at rest and proxied server-side rather than held in the browser. The free Security Scanner is the lighter path — it needs no account. Read from launchguard.dev and suparbase.com on 2026-09-18.

LaunchGuard vs Suparbase — tests as a signed-in user?

LaunchGuard: Yes. “Logged-in tests included: we sign in as a real user, not just a stranger”. Suparbase: No — anonymous probe, plus a simulator. The scanner is explicitly the stranger’s view: “See what a stranger can read from your Supabase project.” Roles are covered separately inside the admin, which can “simulate SELECT/INSERT/UPDATE/DELETE as any role with custom JWT claims. All rolled back.” That is a simulation against your own connection, not a request made by a signed-up account. Read from launchguard.dev and suparbase.com on 2026-09-18. Tests as a signed-in user here means whether the tool authenticates and probes as a real account, rather than only reading what an anonymous stranger can reach.

When should I pick LaunchGuard, and when Suparbase?

LaunchGuard — You ship every week and want the check to run itself. LaunchGuard is the only tool in this table that re-checks on every deploy automatically and keeps a history — “Memory: we remember every result and every call you made” — and at $29/month that is cheaper than buying a one-off report every month. It also covers Firebase, which BreachProbe does not. Suparbase — You want one tool that both RUNS your Supabase project and watches it, rather than a check you run at launch. Suparbase is the only option in this table that is also a working admin — prod→staging sync, a per-row audit log, inline editing, and a live RLS simulator that can “simulate SELECT/INSERT/UPDATE/DELETE as any role with custom JWT claims”. Its free tier is genuinely free forever for up to 3 connections, and at “$12 per user / month” its Agent Sentry keeps a continuous anon-key probe running, which is the cheapest standing watch here. Its five free tools — a Security Scanner, an RLS generator, a schema visualiser, a type generator and a secret scanner — also need no account at all: “no sign-up, no email wall, and no trial timer.”.

WHEN TO PICK ANOTHERWhen each of these is the right pick

BreachProbe does not sell any of these and has nothing to gain from which one you choose — it scores them. Each case below is the one that option genuinely wins.

LaunchGuard

You ship every week and want the check to run itself. LaunchGuard is the only tool in this table that re-checks on every deploy automatically and keeps a history — “Memory: we remember every result and every call you made” — and at $29/month that is cheaper than buying a one-off report every month. It also covers Firebase, which BreachProbe does not.

Suparbase

You want one tool that both RUNS your Supabase project and watches it, rather than a check you run at launch. Suparbase is the only option in this table that is also a working admin — prod→staging sync, a per-row audit log, inline editing, and a live RLS simulator that can “simulate SELECT/INSERT/UPDATE/DELETE as any role with custom JWT claims”. Its free tier is genuinely free forever for up to 3 connections, and at “$12 per user / month” its Agent Sentry keeps a continuous anon-key probe running, which is the cheapest standing watch here. Its five free tools — a Security Scanner, an RLS generator, a schema visualiser, a type generator and a secret scanner — also need no account at all: “no sign-up, no email wall, and no trial timer.”

HEAD TO HEADOther Security scanners for vibe-coded apps compared head to head
SOURCESWhat was checked, and when

Prices and limits move, and a page quoting a stale one is worth less than a page quoting none. Every source is printed here so a reader can check it against the day they are reading this, and a job re-fetches each of these URLs on a schedule and fails when a figure above no longer appears on the page it came from.

TOOLSOURCEGAVEREAD
LaunchGuardwww.launchguard.dev/pricingWhat it costs, What it needs from you, Tests as a signed-in user, Tests one user reading another's rows, Re-checks after you ship, What you get2026-09-18
Suparbasesuparbase.com/pricingWhat it costs, Re-checks after you ship2026-09-18
Suparbasesuparbase.comWhat it needs from you, Tests as a signed-in user, Tests one user reading another's rows, What you get2026-09-18

Last verified 2026-09-18. https://breachprobe.thecompound.tech/compare/launchguard-vs-suparbase