Security scanning · By Paying.co

Find the flaws. Inside and out.

Code reviews what you're building from the inside. Detect examines what you're exposing from the outside. QA tests what your users actually click. Start with a free scan of any domain.

Free scan · No account required · Built by a payments security team
flaw.co · sample report
EXAMPLE REPORT · ILLUSTRATIVE
Bexample.com
WHAT THE SCAN CHECKS
TLS and SSL postureChecked
HTTP headersReview
Exposed servicesChecked
Information disclosureChecked
MCP and AI exposureChecked
Freepassive scan, 5 a month
A to Fgrade plus 0 to 100 score
PCI DSSfindings mapped to requirements
131+EMV L3 certifications behind the team
01 · The free scan

Enter a domain. See what an attacker sees.

The free scan is passive and only reaches publicly accessible elements. Every result includes a grade, scores by family of checks, and findings with their PCI DSS requirement mapping.

TLS

TLS and SSL posture

Protocol and certificate configuration on the domain you enter.

HEADERS

HTTP security headers

The response headers that tell browsers how to protect your users.

SERVICES

Exposed services

Services reachable from the public internet that probably should not be.

DISCLOSURE

Information disclosure

Details your site gives away that help someone plan an attack.

MCP + AI

MCP and AI exposure

Publicly reachable Model Context Protocol endpoints, whether they enforce authentication and encrypted transport, and how CORS is configured. External scanning catches accidentally exposed servers that internal tools cannot see.

REPORT

Grade and branded PDF

A letter grade from A to F, a 0 to 100 score, full unredacted findings and a branded PDF report you can hand to a client or auditor.

02 · Three products, one team

Complete coverage from code to production.

Use one or combine them. Detect and Code are also sold as a bundle.

DETECT

Outside in

Scanning for live domains, applications, infrastructure and MCP and AI endpoints. External vulnerability scanning, PCI and security posture checks, and deep active testing on domains you verify.

CODE

Inside out

Automated security review on every pull request. Checks for secrets, injection, authentication and session issues, and dependency CVEs, through a GitHub App.

QA

What users click

Autonomous exploration of live apps that finds broken flows and console errors, with screenshot evidence and generated Playwright scripts.

03 · How it works

From a free scan to continuous coverage.

01

Scan any domain

No account and no verification needed for the free passive scan.

02

Fix what matters first

Findings come with PCI DSS requirement mappings and clear next steps.

03

Verify and monitor

Verify a domain by DNS TXT record or a well-known file to unlock deep testing, then schedule rescans from weekly to semiannual with change-only email alerts.

Need a human-led test with a QSA behind it? See penetration testing and PCI compliance from Paying.co.

04 · Pricing

Start free. Pay only for what you add.

All prices in US dollars. Current terms are always at flaw.co/pricing.

Detect

Free

$0always free
  • 5 scans a month
  • 90-day scan history
  • Full findings and branded PDF
  • 1 team seat
Run a free scan
Detect

Detect

$15per month
  • Unlimited scans
  • Deep active testing on verified domains
  • Scheduled monitoring, change-only alerts
  • Grade-over-time trending
Get Detect
Detect

Single Deep Scan

$19.99one-time, per domain
  • Passive scan with grades and findings
  • One deep active test
Buy one deep scan
Code

Code

$15per month, up to 5 users
  • Security review on every pull request
  • Secrets, injection, auth and CVE checks
  • GitHub App
Get Code
Best valueBundle

Detect + Code

$24per month, saves $6
  • Everything in Detect
  • Everything in Code
Get the bundle
QA

QA Basic

$10per month, up to 25 URL sessions
  • Autonomous exploration
  • Screenshot evidence
  • Playwright script generation
Get QA Basic
Most popularQA

QA Pro

$50per month, up to 125 URL sessions
  • Everything in QA Basic
  • Higher monthly session allowance
Get QA Pro
Human-led

Penetration testing

Internal and external testing with PCI DSS 11.4 reporting, led by senior engineers and backed by QSA-managed PCI work.
    See penetration testing
    05 · FAQ

    Questions people ask before scanning.

    Is flaw.co free?

    Yes. The passive external scan is free for up to 5 scans a month with no account required. Detect costs $15 a month for unlimited scans and deep active testing, and a single deep scan of one domain is $19.99.

    What does the scan check?

    TLS and SSL posture, HTTP headers, exposed services, information disclosure, and MCP and AI exposure: publicly reachable Model Context Protocol endpoints and whether they enforce authentication.

    What is the MCP and AI exposure check?

    It looks for publicly reachable MCP endpoints, verifies that authentication and encrypted transport are enforced, and evaluates the CORS posture. External scanning catches accidentally exposed servers that internal tools cannot see.

    Do I need to verify my domain?

    No for the free passive scan, which works on any domain. Deep active testing requires you to verify the domain with a DNS TXT record or a well-known file.

    Is the scan safe to run?

    The passive scan is non-intrusive and only reaches publicly accessible elements. The deep tier performs active testing only on domains you have verified, without aggressive techniques.

    How is the grade calculated?

    Each scan returns a letter grade from A to F and a score from 0 to 100, weighted across five families of checks. Findings map to PCI DSS requirements so you know what to fix first.

    Can flaw.co monitor my domains automatically?

    Yes. Detect rescans on a schedule from weekly to semiannual and emails you only when something changes.

    FIND IT BEFORE THEY DO

    Run your first scan in a minute.

    Enter a domain, get a grade and a list of what to fix. No account, no card.

    Run a free scan →