You vibecoded the app. We put it on the internet.

Paste a repo or drop a zip. Vibeship scans it for what breaks in production, fixes what it can, and gives you a live HTTPS URL — usually in about 5 minutes.

Public GitHub, GitLab or Bitbucket repo · no account needed · or upload a zip

Free scans · no account · deploys are in private beta

vibeship.run — from repo to live URL
▸ received ./my-app — 214 files, no Dockerfile needed
✓ security scan — no leaked secrets
✓ container built · pinned @sha256
✓ Postgres provisioned · bound in-cluster
✓ HTTPS issued — Let’s Encrypt
✓ verified — it starts and answers over HTTPS
● live → https://my-app.vibeship.run
my-app.vibeship.runlive

How it works

Six steps from repo to live URL.

Detect, scan and fix are free. Build, deploy and watch are in the deploy beta.

1 / DetectFree

It reads your code and works out how to run it.

Finds your framework and the services your app expects. No Dockerfile? It writes one.

See every step, in detail
github.com/you/my-app — reading 214 files
  • package.json
  • next.config.ts
  • prisma/schema.prisma
  • app/api/checkout/route.ts
  • app/page.tsx
  • vercel.json

Your stack

Next.jsTypeScriptPrisma

Services it needs

PostgresStripe SDK1 cron job
No Dockerfile? Vibeship writes one for your framework.

Why apps break on deploy

It worked on your laptop. Here’s what the internet finds.

Real checks from the free scan, with the finding it would print. These are the ones that leak money or lose data.

  • A secret sent to every visitor

    criticalNEXT_PUBLIC_STRIPE_SECRET_KEY exposes a secret to the browser

    A NEXT_PUBLIC_ or VITE_ prefix puts the value into the JavaScript every visitor downloads. A secret behind it is public the moment you deploy.

  • A key written into the code

    criticalStripe secret key hardcoded in source

    Anyone who opens devtools or downloads your bundle can read it and act as you. It has to live on the server, injected from a secret store.

  • Deleted is not un-leaked

    criticalOpenAI API key committed in git history

    Removing the line does not remove the key from git history — every clone still carries it. It has to be rotated. Checked for GitHub repos.

  • The database that isn’t there

    highDatabase connection string points at localhost

    On your laptop, localhost is where the database runs. In production it is the app’s own container — there is no database there.

  • The database that forgets

    highSQLite persistence needs an explicit production plan

    A SQLite file keeps its data only on storage that survives a restart, and one file can’t be shared safely by more than one copy of the app.

  • API routes anyone can call

    high3 API routes have no authentication check

    Anyone on the internet can call these endpoints directly — reading, writing or deleting data.

Every report also covers risky code patterns (Semgrep) and dependencies with known advisories (Trivy). A critical finding stops a deploy until it’s fixed — or an owner chooses to go ahead with a written reason.

The numbers

Measured, not hoped for.

~5 min to live

A deploy — build, database, certificate and verification — takes about 5 minutes — most deploys land in 4 to 7.

Median of successful deploys over the last 14 days (≈5 min); 9 in 10 finish within about 7.

8 capabilities

checked in every scan, each with its own findings and fixes.

  • Secrets
  • AI
  • Auth
  • Database
  • Payments
  • Email
  • Storage
  • Jobs

Your stack

Detected from your code — no config file to write.

  • Next.js
  • Vite
  • Express
  • NestJS
  • Rails
  • Django
  • FastAPI
  • Flask
  • Laravel
  • Go
  • Spring Boot
  • .NET

Free and beta

What’s free, and what’s in the deploy beta

Free, always

  • Scan any repo — no account needed
  • The full readiness report, with a share link
  • Fix preview: the exact patch for each finding
Scan your repo free

Deploy beta · by invitation

  • Deploy to your own address like your-app.vibeship.run, with HTTPS — databases included
  • Build: signed, digest-pinned images
  • Automatic security repair on a vibeship/deploy branch — your main branch is untouched
  • Verification before anything is called live
  • Roll back to an earlier verified version in two clicks — your code goes back; your database stays as it is now.

Deploying is opening in stages while paid plans get ready. Join the waitlist and we’ll turn it on for your workspace.

Join the deploy beta

Pricing

Coming soon. Scanning is free today.

Paid plans aren’t on sale yet. These are the planned prices; each feature says whether you can use it today or it’s still planned.

Hobby

$0forever

Free security scans

  • Scan any repo — no account needed
  • Readiness score and every finding
  • Fix preview for each finding
  • A share link for every report
Scan your repo free

Pro

Coming soon

$20per month

5,000 credits / month

Planned price — paid plans aren’t on sale yet.

  • Your own address like your-app.vibeship.run, with HTTPS
  • Databases set up when your app needs them
  • Roll back to an earlier verified version in two clicks
  • 5 projectsPlanned
  • Custom domainsPlanned
  • Architecture controls — replicas, database choicePlanned
Join the deploy beta

Team

Coming soon

$40per seat / month

25,000 credits / month

Planned price — paid plans aren’t on sale yet.

  • Everything in Pro
  • Unlimited projects and seatsPlanned
  • Roles and permissionsPlanned
  • Drift alertsPlanned
Join the deploy beta

Free today In the deploy beta today Planned — not built yet

Questions

Plain answers.

Do I need to know Docker or Kubernetes?

No. Vibeship reads your code, works out the framework and the services it needs, and writes a Dockerfile if you don’t have one. If you do have one, it uses yours.

What happens to my code?

A scan only reads it. Fix previews change nothing. When you choose Fix and deploy, each fix is committed separately to a vibeship/deploy branch — your main branch is never touched.

Do I need an account to scan?

No. Scanning is free, needs no account, and every report comes with a link you can share.

When can I deploy?

Deploying is in private beta. It is opening workspace by workspace while paid plans get ready, and we don’t promise a date we can’t keep.

What if a release goes wrong?

Every release is kept. Roll back to an earlier verified version in two clicks — your code goes back; your database stays as it is now. If a new release fails to start, Vibeship puts the previous one back automatically.

What address does my app get?

Its own address like your-app.vibeship.run, with an HTTPS certificate. Bringing your own domain is planned, not built yet.

What isn’t built yet?

Metrics and alerting, Templates, Agent integrations. Also custom domains and paid plans. Nothing on this page depends on them.

Done vibecoding? Time to vibeship.

Start with a free scan: the readiness score, every finding and the fixes — before you decide anything.