Penetration Testing · Powered by flaw.co

Start with your perimeter. Then find everything behind it.

flaw.co gives you a free external scan and a letter grade on your public attack surface in minutes. Paying.co's senior testers take it from there — internal segmentation, CDE isolation, manual exploitation, and the reporting your QSA and the card brand programs actually accept.

lock Free. We scan only what is publicly reachable. No intrusive testing.
How It Fits Together

A scanner and a pen test are not the same thing.

flaw.co tells you what an attacker can see from the outside, instantly and for free. A pen test tells you what they could actually do with it. We built both, and we're clear about where one ends and the other begins.

radar
Layer 01 · Self-serve

flaw.co — External Scan

A passive, non-intrusive scan of everything your servers publicly volunteer: TLS and certificate posture, HTTP security headers, exposed services and open ports, and information disclosure like version banners. You get a letter grade, category scores, and unredacted findings — free.

Free Passive Instant grade
Run a scan on your domain open_in_new
verified_user
Layer 02 · Self-serve

flaw.co — Deep Scan

Active vulnerability testing on domains you've verified you control — CVE detection, exposed path discovery, and misconfiguration testing. Verification runs through a DNS TXT record or a well-known file, so active probes only ever touch infrastructure you own. No fuzzing, no brute force.

Verified domains CVE · Exposure Monitoring
See flaw.co pricing open_in_new
person_search
Layer 03 · Engagement

Paying.co — Full Pen Test

Where automation stops. Senior testers run internal network engagements, segmentation and CDE isolation testing, lateral movement, chained exploits, and business logic attacks — then produce the PCI DSS 11.4 evidence and card brand documentation a scanner cannot generate on its own.

Internal + external Manual exploitation QSA-ready
Book time with a pen tester arrow_forward
info

Where flaw.co stops. flaw.co provides a PCI readiness signal — a clear view of where your external perimeter stands. It is not an Approved Scanning Vendor (ASV) attestation and it is not a PCI compliance certification. Formal validation, internal testing, and QSA-facing evidence come through a Paying.co engagement. We'd rather tell you that up front than have you find out during an audit.

Free to Start

See where your perimeter would fail a review.

No sales call, no procurement cycle, no credit card. Enter a domain, confirm you're authorized to scan it, and get your grade. Most teams find something in the first run.

flaw.co · external scan · passive
B
example.com
Score 82 / 100 · 24 checks run · 4 need attention
TLS / SSL posture · protocol, ciphers, certificatePASS
HSTS · max-age & preloadWEAK
HTTP security headers · CSP missingFAIL
Exposed services · open portsPASS
Information disclosure · server version bannerWEAK
Passive external scan · no intrusive testing performed · a flaw.co security service by Paying.co
Scan my domain arrow_forward About flaw.co
flaw.co Pricing

Start free. Go deep when you need to.

Every plan includes the full passive external scan. Upgrade for active deep testing, unlimited runs, and continuous monitoring — or buy a single deep scan for one domain.

Free
$0
always free
  • check Passive scan — TLS, headers, exposed services, disclosure
  • check Security grade + category scores
  • check Full findings, unredacted
  • check Branded PDF report
  • check 5 scans / month · 90-day history
  • remove No deep active testing
Run a free scan
Pro
$19.99
per month · $15.99/mo billed annually, save 20%
  • check Everything in Free
  • check Deep gated scan — CVE, exposure, misconfiguration
  • check Unlimited scans · indefinite history
  • check Scheduled monitoring — weekly to semiannual
  • check Change alerts — emailed only when something changes
  • check Grade-over-time trend
Upgrade to Pro
Single Deep Scan
$29.99
one-time · one domain
  • check Passive scan + deep active testing
  • check 1 scan · 90-day history
  • check Branded PDF report
  • remove No scheduled monitoring
  • remove No change alerts
Buy a deep scan
How It Works

Passive by default. Active only on domains you own.

The free scan is non-intrusive by design — it opens normal connections and reads what your servers publicly volunteer. No payloads, no endpoints exercised. Active testing is a deliberate, gated step.

visibility

Observe only

The passive scan reads your public surface the way any visitor could. Safe to run on anything, including production, without a change window.

grade

Grade the result

An A–F letter grade and a 0–100 score, weighted across the four check families. Findings show only the checks that didn't pass, against the total that ran.

dns

Verify ownership

Deep active testing requires a DNS TXT record or a well-known file proving you control the domain. Active probes never touch infrastructure you haven't verified.

notifications_active

Watch for drift

On Pro, put any scanned domain on automatic rescan. You're emailed only when something actually changes — a new finding, a resolved one, or a moved grade.

The Full Engagement

What a scanner can't do for you.

flaw.co covers your external surface. A Paying.co pen test covers the rest of the estate — and the parts of PCI DSS 11.4 that require a human tester, a documented methodology, and evidence a QSA will accept.

vpn_lock

Internal & Segmentation

Simulated foothold inside the network. Lateral movement, privileged access paths, CDE isolation — PCI DSS 11.4.5 and 11.4.6 territory.

lan

Network Penetration

Internal enumeration, service exploitation, and validation of the segmentation your PCI scope reduction depends on.

web

Web Applications

OWASP Top 10, auth bypasses, API testing, and the chained business logic flaws automated tooling can't reason about.

smartphone

Mobile Apps

iOS and Android assessment — static and runtime analysis, certificate pinning, secure storage, reverse engineering.

cloud

Cloud Infrastructure

AWS, Azure, and GCP configuration review, IAM analysis, exposed storage, security group rules, IaC hardening.

wifi

Wireless Networks

Wi-Fi testing, rogue AP detection, WPA-2/3 weakness assessment, guest-to-corporate segmentation validation.

psychology

Social Engineering

Phishing simulation, vishing, and pretexting to evaluate the human-factor controls PCI DSS 12 requires.

credit_card

PCI & Card Brand Reporting

Scoped to PCI DSS 4.0 11.4.x, with the reporting Visa AIS, Mastercard SDP, Amex DSOP, and Discover DISC expect on top.

How We Deliver

From free scan to certification-ready report.

Every engagement runs against a documented Statement of Work with named owners on both sides. Focused tests land in 2–4 weeks. Full external + internal + segmentation engagements run 6–10 weeks from kickoff to retest.

radar
Step 01

Free flaw.co scan

Start on your own. Run the passive external scan, get your grade, and see the findings before you talk to anyone. Free, no obligation.

event_available
Step 02

Scoping call

Bring us the scan. We map it against your compliance obligations — PCI DSS, Visa AIS, Mastercard SDP, Amex DSOP, Discover DISC — and return a fixed scope and price.

travel_explore
Step 03

Discovery & deep scan

Full attack surface mapping, internal enumeration, application crawling, and cloud configuration review — with flaw.co's deep active testing on the verified external surface.

person_search
Step 04

Manual exploitation

Senior testers validate findings with actual exploitation — chained vulnerabilities, segmentation gaps, business logic flaws. Proof, not theoretical risk.

description
Step 05

Certification-ready report

Scope, methodology, findings, evidence, and a sequenced remediation path — formatted for QSA submission and card brand program reviewers.

update
Step 06

Retest & monitoring

Retest after remediation, validate every closed finding, then keep the perimeter under continuous flaw.co monitoring so next year starts from a known baseline.

Ready to Get Started?

Run the free scan. Then get on the calendar.

Start with flaw.co — it costs nothing and takes minutes. When you're ready to scope the real engagement, pick a time that works and you'll be sitting across from a senior pen tester, not a sales rep.

event_available

Pick your own time

Grab a 30-minute slot on the calendar — no back-and-forth over email.

engineering

You'll talk to an engineer

The person you brief is the person who scopes the test.

handshake

No-obligation review

We'll help you scope it against your budget and timeline.

language

We speak your language

English, Spanish, and Polish — fluent across our team.

For ISVs· Acquirers· Fintechs· Unattended Commerce· Developers