Shipping AI is easy.
Making it ready — and provable — isn't.
Most AI features get built and shipped. Far fewer are actually production-grade — reliable, safe, and compliant, not just working. ShipSmith holds every AI workflow to that bar — whether you're shipping it now or it's been live for months — finds what's missing, and keeps it there. Start with a free readiness scan.
No credit card required · No sales call · Works with GitHub
Ensure every AI workflow meets the same production and compliance bar.
Where do you want to start?
Production readiness →
Hold every workflow to the same bar as AI spreads across your codebase: evaluation, guardrails, observability, reliability, cost.
Compliance readiness →
Make your AI audit-ready. Turn what your team built into evidence that passes a security review — mapped to the EU AI Act, ISO/IEC 42001 and GDPR.
Scanning repo: github.com/acme/backend
───────────────────────────────────────
✓ Found: OpenAI GPT-4 call in /src/support/classify.ts
✓ Found: LangChain agent in /src/sales/outreach.py
✓ Found: Anthropic Claude call in /src/docs/summarizer.ts
✓ Found: LangGraph workflow in /src/onboarding/flow.py
───────────────────────────────────────
4 AI workflows discovered.
Readiness score: 3/9 dimensions passing.
→ Sign up to close the gaps — and keep them closed as you ship
Free for your first workflow · No credit card · Works with GitHub
You build well.
But does every workflow meet the same bar, and can you prove it?
AI spreads faster than you can track it
You built an AI feature in Q3. Another team shipped one in Q4. The first got careful evals; the tenth, under deadline, didn't. No one has a full map of every workflow in production.
Checklists don't scale
A spreadsheet works for one workflow. At 10 workflows across 5 teams, nobody is tracking anything consistently and gaps pile up silently.
Then someone asks you to prove it
A customer's security team or an auditor asks you to show your AI is safe and governed — mapped to the EU AI Act and ISO/IEC 42001. Assertions and screenshots don't pass a review. Evidence does, and most teams don't have it.
A score is where it starts — not where it ends.
Anyone can hand you a score. ShipSmith runs everything after it — closing the gaps, proving compliance, and keeping every workflow at the bar as your code changes.
Discover
Connect your repo and ShipSmith analyzes every file, surfacing each LLM call, agent, chain and workflow — including the shadow workflows that accumulate when teams move fast. It scores each against 115+ production readiness controls across 9 dimensions, and assesses each against the EU AI Act and ISO/IEC 42001 across 7 compliance dimensions.
Fix
See exactly which controls are failing — production and compliance — and why. Remediation guidance is mapped to each gap, with owners, priorities and progress tracked as your team closes them.
Prove
Turn what your team built into evidence a reviewer will accept: a production readiness grade and a compliance grade mapped to the EU AI Act and ISO/IEC 42001, with the control-by-control record you can put in front of a customer's security team or an auditor.
Learn
Operator Academy — coming soonEvery gap comes with in-product guidance — what good looks like, the common mistake, why it matters. Operator Academy takes it further: structured, role-based modules tuned to your specific gaps.
Sustain
A workflow is never “done” when it ships. Re-assess on demand, carry remediation forward across runs, and catch regressions the moment a workflow slips below the bar.
Two ways to run a scan.
Connect your repo in the browser, or drive the same scan from your terminal. Either way, discovery and scoring run on our side, on the same 115+ controls.
Connect your repo
Point ShipSmith at a GitHub repository. We discover every AI workflow and score it, and your readiness number appears right on screen.
- 1Sign in, paste a repo URL
- 2We scan it server-side
- 3Score + top gaps on screen, report by email
Scan from Claude Code
One command inside Claude Code. It reads your repo's Git identity, runs the scan on our backend, and opens the same report, without leaving the terminal.
> /shipsmith:scan
▸ repo · github.com/acme/backend
▸ enqueued · discovering workflows…
✓ 4 workflows · scored on 115+ controls
→ report opened in your browser
Rolling out to design partners first.
However you start it, discovery, the 115+ control scoring, and the findings run server-side on ShipSmith's tokens. Nothing scans or analyzes your code locally.
115+ controls. 9 dimensions. One readiness score.
Grounded in NIST AI RMF, AWS GenAI Lens, Microsoft Responsible AI, and OWASP LLM Top 10.
Data Foundation
The AI is only as good as what it's fed.
Model & Architecture
Is the right model being used the right way?
Evaluation & QA
The dividing line between production systems and demos.
Observability & Monitoring
You cannot improve what you cannot see.
Resilience & Production Engineering
Does this survive the real world or just the demo?
Security & Compliance
Rarely the fun part of shipping — first thing a buyer asks.
Cost Management
Unchecked AI costs kill promising projects.
Adoption & Change Management
Mostly people and process — the part that lives outside the code.
AI Governance & Risk Management
The scaffolding for responsible AI at scale.
120+ controls. 7 dimensions. One compliance grade.
Compliance readiness is its own assessment — grounded in the EU AI Act and ISO/IEC 42001, spanning both what's in the code and the policies and process behind it.
Governance
Who owns the AI, what the policy says, and how it's held accountable.
Risk Management
Finding where an AI system can cause harm — and having a plan before it does.
Human Oversight
A person stays in control — able to review, override and stop the system.
Auditability
If a regulator asks what happened, the logs can reconstruct it.
Data & Privacy
Where personal data enters the model, and the safeguards around it.
Transparency
People affected by the AI know it's AI — and can get an explanation.
Lifecycle
Keeping the system safe as it changes, and handling incidents when they happen.
Free for your first workflow.
- Discover all AI workflows in your repo
- Automated production readiness scan — 1 workflow, scored across 9 dimensions
- Automated compliance scan — 1 workflow: EU AI Act risk tier + the controls verifiable from your code
- Top failing dimensions, ranked
- 1 user
Tailored to your team. Book a call to discuss.
- Everything in Free
- Every discovered workflow assessed, not just one
- Full compliance audit — the policy & process controls resolved with our team, graded across all 120+ controls (EU AI Act & ISO/IEC 42001)
- Full remediation plan per workflow — owners, priorities, progress tracked
- Re-assess on demand to catch regressions and keep workflows ready
- Control-level breakdown — all 115+ production & 120+ compliance controls, as audit evidence
- In-product guidance on every gap: what good looks like, and why
- PDF readiness report + multiple users
Common questions
How does the codebase scanner work?+
Do you store my code?+
What if I don't want to connect my repo?+
What frameworks are supported?+
How is this different from a spreadsheet checklist?+
Is compliance readiness the same as the production scan?+
How long does the scan take?+
Your AI is already in production.
Is it ready?
Connect your repo, discover your AI workflows, and see where every workflow stands on production and compliance readiness.
Scan Your Repo, Free →No credit card required. Most scans finish in minutes. We email your report either way.