Production- & compliance-ready AI, from first ship onward · Free for your first workflow

Shipping AI is easy.
Making it ready — and provable — isn't.

Most AI features get built and shipped. Far fewer are actually production-grade — reliable, safe, and compliant, not just working. ShipSmith holds every AI workflow to that bar — whether you're shipping it now or it's been live for months — finds what's missing, and keeps it there. Start with a free readiness scan.

No credit card required · No sales call · Works with GitHub

shipsmith scan

Scanning repo: github.com/acme/backend

───────────────────────────────────────

✓ Found: OpenAI GPT-4 call in /src/support/classify.ts

✓ Found: LangChain agent in /src/sales/outreach.py

✓ Found: Anthropic Claude call in /src/docs/summarizer.ts

✓ Found: LangGraph workflow in /src/onboarding/flow.py

───────────────────────────────────────

4 AI workflows discovered.

Readiness score: 3/9 dimensions passing.

→ Sign up to close the gaps — and keep them closed as you ship

Production readiness
9
dimensions
115+
controls
Grounded in NIST, OWASP, AWS & Microsoft
Compliance readiness
7
dimensions
120+
controls
Grounded in the EU AI Act & ISO/IEC 42001

Free for your first workflow · No credit card · Works with GitHub

You build well.
But does every workflow meet the same bar, and can you prove it?

👁

AI spreads faster than you can track it

You built an AI feature in Q3. Another team shipped one in Q4. The first got careful evals; the tenth, under deadline, didn't. No one has a full map of every workflow in production.

📋

Checklists don't scale

A spreadsheet works for one workflow. At 10 workflows across 5 teams, nobody is tracking anything consistently and gaps pile up silently.

🛡

Then someone asks you to prove it

A customer's security team or an auditor asks you to show your AI is safe and governed — mapped to the EU AI Act and ISO/IEC 42001. Assertions and screenshots don't pass a review. Evidence does, and most teams don't have it.

A score is where it starts — not where it ends.

Anyone can hand you a score. ShipSmith runs everything after it — closing the gaps, proving compliance, and keeping every workflow at the bar as your code changes.

01

Discover

Connect your repo and ShipSmith analyzes every file, surfacing each LLM call, agent, chain and workflow — including the shadow workflows that accumulate when teams move fast. It scores each against 115+ production readiness controls across 9 dimensions, and assesses each against the EU AI Act and ISO/IEC 42001 across 7 compliance dimensions.

02

Fix

See exactly which controls are failing — production and compliance — and why. Remediation guidance is mapped to each gap, with owners, priorities and progress tracked as your team closes them.

03

Prove

Turn what your team built into evidence a reviewer will accept: a production readiness grade and a compliance grade mapped to the EU AI Act and ISO/IEC 42001, with the control-by-control record you can put in front of a customer's security team or an auditor.

04

Learn

Operator Academy — coming soon

Every gap comes with in-product guidance — what good looks like, the common mistake, why it matters. Operator Academy takes it further: structured, role-based modules tuned to your specific gaps.

05

Sustain

A workflow is never “done” when it ships. Re-assess on demand, carry remediation forward across runs, and catch regressions the moment a workflow slips below the bar.

/For developers

Two ways to run a scan.

Connect your repo in the browser, or drive the same scan from your terminal. Either way, discovery and scoring run on our side, on the same 115+ controls.

In the browserAvailable now

Connect your repo

Point ShipSmith at a GitHub repository. We discover every AI workflow and score it, and your readiness number appears right on screen.

  • 1Sign in, paste a repo URL
  • 2We scan it server-side
  • 3Score + top gaps on screen, report by email
In your terminalPreview

Scan from Claude Code

One command inside Claude Code. It reads your repo's Git identity, runs the scan on our backend, and opens the same report, without leaving the terminal.

claude code

> /shipsmith:scan

▸ repo · github.com/acme/backend

▸ enqueued · discovering workflows…

✓ 4 workflows · scored on 115+ controls

→ report opened in your browser

Request early access →

Rolling out to design partners first.

However you start it, discovery, the 115+ control scoring, and the findings run server-side on ShipSmith's tokens. Nothing scans or analyzes your code locally.

Free for your first workflow.

Free
$0
  • Discover all AI workflows in your repo
  • Automated production readiness scan — 1 workflow, scored across 9 dimensions
  • Automated compliance scan — 1 workflow: EU AI Act risk tier + the controls verifiable from your code
  • Top failing dimensions, ranked
  • 1 user
Scan Your Repo, Free →
Pro
Let's talk

Tailored to your team. Book a call to discuss.

  • Everything in Free
  • Every discovered workflow assessed, not just one
  • Full compliance audit — the policy & process controls resolved with our team, graded across all 120+ controls (EU AI Act & ISO/IEC 42001)
  • Full remediation plan per workflow — owners, priorities, progress tracked
  • Re-assess on demand to catch regressions and keep workflows ready
  • Control-level breakdown — all 115+ production & 120+ compliance controls, as audit evidence
  • In-product guidance on every gap: what good looks like, and why
  • PDF readiness report + multiple users
Book a call →

Common questions

How does the codebase scanner work?+
We use an AI agent that reads your repository and identifies LLM API calls, agent frameworks (LangChain, LangGraph, etc.), and AI workflow patterns. It works with Python, TypeScript, JavaScript, and Java repositories.
Do you store my code?+
No. The scanner reads your code to identify AI workflow patterns and does not persist any source code. We store only the workflow metadata: file paths, framework detected, and workflow description.
What if I don't want to connect my repo?+
You can register your AI workflow manually. Just describe what it does and which frameworks it uses. The assessment works exactly the same way.
What frameworks are supported?+
OpenAI SDK, Anthropic SDK, LangChain, LangGraph, LlamaIndex, AWS Bedrock, Hugging Face, Mastra, and raw REST API calls to any LLM provider.
How is this different from a spreadsheet checklist?+
A spreadsheet doesn't find your workflows for you, doesn't score them consistently, doesn't track remediation, and doesn't update as your codebase changes. ShipSmith does all four.
Is compliance readiness the same as the production scan?+
No — it's a separate assessment. Production readiness scores each workflow across 9 engineering dimensions (evals, guardrails, observability, cost, and more). Compliance readiness assesses each workflow across 7 governance dimensions against the EU AI Act and ISO/IEC 42001, classifies its risk tier, and produces a compliance grade and evidence you can put in front of a security review or regulator. Same discovery, two bars.
How long does the scan take?+
Most scans finish in a few minutes and your score appears right on screen. Very large monorepos take longer, and when demand is high we queue your scan and email the full report as soon as it's ready, usually within a few hours. Either way you don't have to wait around: we always email you the report.

Your AI is already in production.
Is it ready?

Connect your repo, discover your AI workflows, and see where every workflow stands on production and compliance readiness.

Scan Your Repo, Free →

No credit card required. Most scans finish in minutes. We email your report either way.