Code reviews what you're building from the inside. Detect examines what you're exposing from the outside. QA tests what your users actually click. Start with a free scan of any domain.
The free scan is passive and only reaches publicly accessible elements. Every result includes a grade, scores by family of checks, and findings with their PCI DSS requirement mapping.
Protocol and certificate configuration on the domain you enter.
The response headers that tell browsers how to protect your users.
Services reachable from the public internet that probably should not be.
Details your site gives away that help someone plan an attack.
Publicly reachable Model Context Protocol endpoints, whether they enforce authentication and encrypted transport, and how CORS is configured. External scanning catches accidentally exposed servers that internal tools cannot see.
A letter grade from A to F, a 0 to 100 score, full unredacted findings and a branded PDF report you can hand to a client or auditor.
Use one or combine them. Detect and Code are also sold as a bundle.
Scanning for live domains, applications, infrastructure and MCP and AI endpoints. External vulnerability scanning, PCI and security posture checks, and deep active testing on domains you verify.
Automated security review on every pull request. Checks for secrets, injection, authentication and session issues, and dependency CVEs, through a GitHub App.
Autonomous exploration of live apps that finds broken flows and console errors, with screenshot evidence and generated Playwright scripts.
No account and no verification needed for the free passive scan.
Findings come with PCI DSS requirement mappings and clear next steps.
Verify a domain by DNS TXT record or a well-known file to unlock deep testing, then schedule rescans from weekly to semiannual with change-only email alerts.
Need a human-led test with a QSA behind it? See penetration testing and PCI compliance from Paying.co.
All prices in US dollars. Current terms are always at flaw.co/pricing.
Yes. The passive external scan is free for up to 5 scans a month with no account required. Detect costs $15 a month for unlimited scans and deep active testing, and a single deep scan of one domain is $19.99.
TLS and SSL posture, HTTP headers, exposed services, information disclosure, and MCP and AI exposure: publicly reachable Model Context Protocol endpoints and whether they enforce authentication.
It looks for publicly reachable MCP endpoints, verifies that authentication and encrypted transport are enforced, and evaluates the CORS posture. External scanning catches accidentally exposed servers that internal tools cannot see.
No for the free passive scan, which works on any domain. Deep active testing requires you to verify the domain with a DNS TXT record or a well-known file.
The passive scan is non-intrusive and only reaches publicly accessible elements. The deep tier performs active testing only on domains you have verified, without aggressive techniques.
Each scan returns a letter grade from A to F and a score from 0 to 100, weighted across five families of checks. Findings map to PCI DSS requirements so you know what to fix first.
Yes. Detect rescans on a schedule from weekly to semiannual and emails you only when something changes.
Enter a domain, get a grade and a list of what to fix. No account, no card.
Run a free scan →