BREACHPROBE / LAUNCHGUARD
BreachProbe vs LaunchGuard
Two external scanners for apps built with Lovable, Bolt, v0 or Supabase, compared on the six things that decide which one you want.
2 compared· 6 criteria, identical for every column· every competitor figure read off that company's own page· last verified 2026-09-18
These are not really competing products, and the honest answer depends on one question: is this a launch check or a habit? If you ship every week and want the check to run itself, buy LaunchGuard — $29/month gets a re-check on every deploy and a memory of every result, and paying once a month beats buying a one-off report once a month. If you want to know right now whether the thing you just shipped is serving its database to strangers, BreachProbe answers that with a URL, no account and nothing installed, and the free scan is the whole scan. The two agree on the check that matters most: both sign in as a real user, and both test whether one account can read another's rows — which is the only test that separates a row-level security policy that works from one that merely exists.
| CRITERION | LAUNCHGUARD | |
|---|---|---|
| What it costs | Free · Pro $29/month“Free $0 forever … Pro $29 / month”. The free tier is not a findings paywall: “It is not a paywall on findings.” | Free scan · $19 report · $39 with monitoringThe scan is free. “$19 one payment, one report”; “$39 one payment, 30 days” adds the nightly re-scan. |
| What it needs from you | A URL; sign-up to see full key details“Signing up (still free, no card) reveals the full leaked key and the fix prompt.” | One URL“No account · nothing installed · read-only · one URL”. |
| Tests as a signed-in user | Yes“Logged-in tests included: we sign in as a real user, not just a stranger”. | YesIt creates its own accounts rather than asking for yours. |
| Tests one user reading another's rows | Yes, as a saved guardThe free tier saves “up to 2 guards … for a cross-user leak, a payment bypass, or any rule you name”. | YesThe page lists it as a row a passive scan cannot test: "rows one user can read that belong to another", where a passive scan "cannot test it" and the probe "counts them, table by table". |
| Re-checks after you ship | Every deploy, on Pro“It re-checks on every deploy, automatically, the moment you ship”. | Nightly for 30 days, on the $39 tier“a nightly re-scan for 30 days and an email the moment a new critical or high issue appears”. |
| What you get | Findings, the request receipt, and a fix“Every finding, and the receipt: the exact request we sent and what your app sent back”. | Findings, a cross-tenant table, a written fix"Every finding located, table by table, a written fix per issue." |
Every figure below was read off that company's own page; each source URL and the date it was read are listed at the foot of this page. BreachProbe is one of the 2 compared and is the one publishing this table.
| TESTS AS A SIGNED-IN USER | whether the tool authenticates and probes as a real account, rather than only reading what an anonymous stranger can reach |
|---|---|
| TESTS ONE USER READING ANOTHER'S ROWS | the two-account test. It is the only check that can tell a working row-level security policy from one that is merely present |
Is LaunchGuard free?
There is a free tier and it is not a findings paywall — LaunchGuard's pricing page states "Free $0 forever" and "It is not a paywall on findings." The free scan includes all three engines, logged-in tests, and the receipt for every finding. Pro is $29/month and adds the parts a one-off scan cannot do: it re-checks on every deploy automatically, keeps unlimited saved guards where free keeps two, and remembers every result.
What does BreachProbe cost?
The scan is free, with no account and nothing to install — you paste a URL. A full report is $19 as a one-off payment, covering where every finding is, the cross-tenant result table by table, and a written fix per issue. $39 buys the same report plus a nightly re-scan for 30 days and an email the moment a new critical or high issue appears.
Do either of them test whether one user can read another user's data?
Yes, and it is the single most important row in the table. BreachProbe signs up two accounts and reports a cross-tenant result table by table. LaunchGuard covers it as a saved "guard" — its free tier keeps up to two, named on its pricing page as "a cross-user leak, a payment bypass, or any rule you name". A scanner that only looks at what an anonymous stranger can reach cannot tell a working RLS policy from a broken one, because both of them refuse the stranger.
Do I still need one of these if Supabase has a Security Advisor?
They answer different questions, so running the Security Advisor first is right and running only it is not. The advisor reads your project's configuration from inside the dashboard and runs automatically — its published checks include "auth users exposed" and unindexed foreign keys. It does not sign in to your shipped app as two different users and try to read one's rows with the other's session. That is what an external scanner does, and it is the check that catches a policy which is present, enabled, and wrong.
BreachProbe is not the right answer to every version of this question, and a comparison page that pretends otherwise is an advert. Each case below is a real one.
You ship every week and want the check to run itself. LaunchGuard is the only tool in this table that re-checks on every deploy automatically and keeps a history — “Memory: we remember every result and every call you made” — and at $29/month that is cheaper than buying a one-off report every month. It also covers Firebase, which BreachProbe does not.
Prices and limits move, and a page quoting a stale one is worth less than a page quoting none. Every source is printed here so a reader can check it against the day they are reading this, and a job re-fetches each of these URLs on a schedule and fails when a figure above no longer appears on the page it came from.
| TOOL | SOURCE | GAVE | READ |
|---|---|---|---|
| LaunchGuard | www.launchguard.dev/pricing | What it costs, What it needs from you, Tests as a signed-in user, Tests one user reading another's rows, Re-checks after you ship, What you get | 2026-09-18 |
| BreachProbe | breachprobe.thecompound.tech/ | What it costs, What it needs from you, Tests as a signed-in user, Tests one user reading another's rows, Re-checks after you ship, What you get | 2026-09-18 |
Last verified 2026-09-18. https://breachprobe.thecompound.tech/vs/launchguard