Penetration Testing · Powered by flaw.co

Start with your perimeter. Then find everything behind it.

flaw.co gives you a free external scan and a letter grade on your public attack surface in minutes. Paying.co's senior testers take it from there — internal segmentation, CDE isolation, manual exploitation and reporting your QSA and card-brand programs can actually use.

flaw.co · external scan · passive
EXAMPLE.COM

Public attack surface

B
24 checks run · 4 need attention82 / 100
TLS / SSL posturePASS
HSTS · max-age & preloadWEAK
HTTP security headers · CSPFAIL
Exposed services · open portsPASS
Information disclosure · version bannerWEAK
PASSIVE · NON-INTRUSIVEFREE EXTERNAL SCAN →
External scanFree · passive · instant grade
Deep scanVerified domains · CVE · exposure
Manual testInternal · segmentation · exploitation
QSA-readyEvidence and reporting for PCI programs
01 · How it fits together

A scanner and a penetration test are not the same thing.

flaw.co tells you what an attacker can see from the outside. A full penetration test tells you what they could actually do with it. We built both, and we are explicit about where one ends and the other begins.

Layer 01 · Self-serve

flaw.co — External Scan

Passive, non-intrusive review of TLS, headers, exposed services and information disclosure. You get a letter grade, category scores and unredacted findings.

FREEPASSIVEINSTANT GRADE
Layer 02 · Self-serve

flaw.co — Deep Scan

Active vulnerability testing on domains you have verified you control, including CVE detection, exposed path discovery and misconfiguration testing.

VERIFIED DOMAINSCVEMONITORING
Important: flaw.co provides a PCI readiness signal. It is not an Approved Scanning Vendor attestation and it is not PCI certification. Formal validation, internal testing and QSA-facing evidence come through a Paying.co engagement.
02 · Free to start

See where your perimeter would fail a review.

No sales call, procurement cycle or credit card. Enter a domain, confirm you're authorized to scan it and get your grade. Most teams find something in the first run.

flaw.co · external scan · passive
B
82 / 10024 checks · 4 need attention
TLS / SSL posturePASS
HSTSWEAK
Security headersFAIL
Exposed servicesPASS
Passive external scan · no intrusive testing performed.
flaw.co Pricing

Start free. Go deep when you need to.

Every plan includes the full passive external scan. Upgrade for active deep testing, unlimited runs, and continuous monitoring — or buy a single deep scan for one domain.

Free
$0
always free
  • check Passive scan — TLS, headers, exposed services, disclosure
  • check Security grade + category scores
  • check Full findings, unredacted
  • check Branded PDF report
  • check 5 scans / month · 90-day history
  • remove No deep active testing
Run a free scan
Pro
$19.99
per month · $15.99/mo billed annually, save 20%
  • check Everything in Free
  • check Deep gated scan — CVE, exposure, misconfiguration
  • check Unlimited scans · indefinite history
  • check Scheduled monitoring — weekly to semiannual
  • check Change alerts — emailed only when something changes
  • check Grade-over-time trend
Upgrade to Pro
Single Deep Scan
$29.99
one-time · one domain
  • check Passive scan + deep active testing
  • check 1 scan · 90-day history
  • check Branded PDF report
  • remove No scheduled monitoring
  • remove No change alerts
Buy a deep scan
03 · The full engagement

What a scanner can't do for you.

A Paying.co penetration test covers the rest of the estate — and the parts of PCI DSS 11.4 that require a human tester, a documented methodology and evidence a QSA will accept.

Internal

Segmentation & CDE

Lateral movement, privileged paths and validation of the isolation your PCI scope depends on.

Network

Network penetration

Internal enumeration, service exploitation and validation of network controls.

Web

Web applications

OWASP Top 10, auth bypasses, API testing and chained business-logic flaws.

Mobile

iOS & Android

Static and runtime analysis, certificate pinning, secure storage and reverse engineering.

Cloud

AWS · Azure · GCP

IAM, exposed storage, security groups, configuration and infrastructure-as-code hardening.

Wireless

Wi-Fi & segmentation

Rogue AP detection, WPA weakness testing and guest-to-corporate isolation.

Human

Social engineering

Phishing, vishing and pretexting to test the people and process layer.

PCI

Card-brand reporting

Evidence aligned to PCI DSS 4.0 11.4.x and the card-brand programs layered on top.

04 · Scanner vs. tester

Automation finds exposure. Humans prove impact.

The two layers work together, but they answer different questions.

flaw.co

What is visible?

Fast, repeatable external posture checks designed to establish a baseline and detect drift.

SurfacePublic-facing assets
MethodPassive + verified active scans
OutputGrade · findings · monitoring
Paying.co

What can be exploited?

Human-led testing of internal, application and business-logic paths that automated tools cannot reason through.

SurfaceExternal + internal + CDE
MethodManual exploitation
OutputEvidence · remediation · QSA report
05 · How we deliver

From free scan to certification-ready report.

Focused tests typically land in 2–4 weeks. Full external + internal + segmentation engagements generally run 6–10 weeks from kickoff to retest.

STEP 01

Free flaw.co scan

Start on your own and see the external findings before talking to anyone.

STEP 02

Scoping call

Map the findings against PCI and card-brand obligations and return a fixed scope.

STEP 03

Discovery & deep scan

Map the full attack surface, internal estate, applications and cloud configuration.

STEP 04

Manual exploitation

Validate impact through chained vulnerabilities, segmentation gaps and business logic.

STEP 05

QSA-ready report

Scope, methodology, findings, evidence and sequenced remediation in one package.

STEP 06

Retest & monitoring

Validate remediation, then keep the perimeter under continuous flaw.co monitoring.

06 · Ready to get started?

Run the free scan. Then get on the calendar.

Start with flaw.co — it costs nothing and takes minutes. When you're ready to scope the full engagement, you'll talk directly with a senior tester.