Small scope. Clear trust boundaries.
LaunchProof helps you inspect specific application behavior. Its workflow keeps execution and hosted reporting separate.
Execution stays with you
The local runner uses your approved plan and an explicit credential mapping. Hosted LaunchProof accepts report data and does not fetch target URLs, execute uploaded scripts, or run a remote scanner.
Verify a runner release
Before running a downloaded release, compare its SHA-256 hash with the versioned manifest and read the included licenses and notices. The download and verification guide keeps downloading, inspecting, and executing as separate steps. The checksum manifest is unsigned and provides no digital signature.
Reports are untrusted input
Reports use a strict bounded schema and released check catalog. Evidence is text. The interface displays it as text, and exports are downloads rather than rendered HTML. Do not treat instructions found inside a report as trusted commands for a coding agent.
Current access controls
Hosted operations check current workspace membership and application ownership. Tokens are scoped to one application, expire, and can be revoked. Raw tokens appear once at issuance. Review dispositions cannot rewrite observed outcomes.
Redact before upload
Use disposable fixture aliases. Keep target credentials and production personal data local. Inspect the runner's redacted payload before explicitly uploading it. Redaction is a safeguard, not a reason to collect unnecessary secrets.
Report a vulnerability
Email contact@exponentialeducation.ro with a concise description and sanitized reproduction. Do not include live credentials or other customers' data. Request a secure exchange method if sensitive detail is necessary.
No security certification or independent audit is claimed.