Flaw.co is Paying.co's security scanning platform — built by a payments engineering team that has delivered 131+ EMV Level 3 certifications across the US, Canada, Europe, LATAM, and the Caribbean. It covers two live products today: Detect, an outside-in external security and PCI readiness scanner, and Code, automated security review on every pull request. Both are built for teams who need real findings mapped to real fixes, not another dashboard to babysit.
🔍 Detect — see what an attacker sees
Detect scans your live domains, applications, infrastructure, and MCP/AI endpoints from the outside in. No agent, no install, nothing to deploy — it reads what your servers already tell the public internet.
Every scan examines five check families:
TLS & certificates — Protocol versions, cipher strength, certificate validity and expiry, HSTS. The layer everything else on your surface depends on.
Security headers — Content-Security-Policy, frame options, transport security, and the rest of the header set browsers use to defend your users.
Exposed surface — Open ports and reachable services. What's actually facing the internet is often more than what you meant to expose.
Information disclosure — Version banners, server fingerprints, and the small volunteered details that tell an attacker exactly which exploit to reach for.
MCP / AI exposure — Publicly reachable Model Context Protocol endpoints, and whether they enforce authentication, encrypt transport, and keep a safe CORS posture. This is the surface AI agents open that nothing else scans for — most AI-security tooling only watches MCP activity from inside your cloud account, so it can't see a server your team spun up and accidentally left public. Detect takes the attacker's view and scans from the outside with nothing but your domain.
Each scan returns a letter grade (A–F) and a 0–100 score, weighted across all five families. A finding is only a check that didn't pass — no guessing, no invented severity — and every finding names the specific control to change and the PCI DSS v4.0.1 requirement it maps to, where an honest mapping exists.
Passive vs. Deep scanning:
✓ Passive is non-intrusive by design — normal connections, publicly volunteered data only, no payloads sent. Free on any domain, right now.
✓ Deep adds active testing for CVEs, exposed paths, misconfigurations, and unauthenticated MCP tool-catalog disclosure — but only on domains you've proven you control, with ownership verified in the scan worker itself, not just the UI.
Continuous monitoring: any scanned domain on Detect can be set to automatic rescan — weekly, biweekly, monthly, quarterly, or semiannual. Alerts are change-only: a new finding, a resolved one, or a grade that moved. A rescan that finds nothing new sends nothing at all, so an email always means something worth reading.
💻 Code — catch it before it merges
Code is automated, security-scoped review on every pull request — not a linter, not a general code-quality bot. Every check exists to catch something that becomes an incident if it ships, and findings post directly as comments on the PR, where your team already works.
Four review categories, every pull request:
Secrets & credentials — API keys, tokens, and connection strings that made it into a diff before anyone noticed. The single most common way a breach starts.
Injection risks — SQL, command, and template injection patterns introduced by new or changed code, flagged with the specific line and why it's exploitable.
Auth & session changes — Modifications to authentication, authorization, or session handling get closer scrutiny — this is where a one-line change quietly becomes a privilege escalation bug.
Dependency CVEs — New or updated packages checked against known vulnerabilities before they land in your default branch, not discovered weeks later in a scheduled audit.
Setup is a GitHub App install — pick which repos get security review, no CI pipeline to configure and no YAML to maintain unless you want to tune it. Every pull request against a connected repo triggers a review scoped to what actually changed, not the whole codebase, so reviews stay fast and relevant.
🏷 Pricing — start free, go deep when you need to
Free — $0. Full passive Detect scan, up to 5 scans a month, all five check families, a real letter grade.
Detect — $15/mo. Unlimited scans, deep active testing on verified domains, scheduled rescans, change-only alerts.
Single Deep Scan — $19.99. One-time active deep scan for a single verified domain, no subscription required.
Code — $15/mo. Automated security review on every pull request across your connected repos, up to 5 users included, billed flat per organization — not metered per seat or per PR.
Detect + Code bundle — $24/mo. Both products together, saving $6/mo over buying separately.
🛡 Why it matters
Detect covers what's deployed. Code covers what's shipping. Together they close the loop between what you're building and what you're exposing — the same engineering discipline Paying.co brings to payment certification and processor integration, applied to security posture and PCI readiness.
Every scan and every review category is designed around one principle: a finding is only useful if it tells you exactly what to fix and why it matters. No opaque scores, no black-box severity — just real findings, mapped to real requirements.
🔗 flaw.co
🔗 Explore Detect
🔗 Explore Code
🔗 Book a meeting
🔗 paying.co