External security scan

Find the flaws. Inside and out.

Code reviews what you're building from the inside. Detect examines what you're exposing from the outside.

Enter a domain — every scan includes MCP / AI exposure alongside TLS, headers, exposed services, and disclosure.
Free — no account required
We scan only what is publicly reachable. A flaw.co security service by Paying.co.
Three products, one team
Live now
[•]
Product 01 · Flaw.co

Detect

Outside-in · Monitoring · PCI ready

Outside-in scanning for your live domains, applications, infrastructure, and MCP / AI endpoints.

External vulnerability scanningPCI & security posture checksMCP & AI exposure detection
Explore Detect →
Live now
</>
Product 02 · Flaw.co

Code

Inside-out · Pull requests · GitHub App

Automated security review on every pull request, integrated into your development workflow.

Secrets, injection & auth/session reviewDependency CVE detectionGitHub pull request integration
Review your code →
Live now
[ ]
Product 03 · Flaw.co

QA

Post-deploy · Autonomous · No test suite

Autonomous exploration testing for your live app — drop in a URL and find broken flows before your users do.

Broken-flow & console-error detectionScreenshot & Playwright script evidenceOn-demand, no repo connection required
Explore QA →
🏷️
Complete coverage from code to production.
Get Detect + Code together for $24/mo — save $6/mo over buying separately. See bundle pricing →

Built by a payments security team

Domains scanned
Scans run
Findings surfaced
131+
EMV L3 certifications delivered

Scan counts update live. Certification record is Paying.co's, across US, Canada, Europe, LATAM and the Caribbean.

Example report preview

Actionable findings. Clear next steps.

Every scan returns a grade, a score for each of the five families, and findings written out in full — what we detected, why it matters, how to fix it, and the PCI DSS requirement it maps to.

View sample report →

Frequently asked questions

Is flaw.co free?
Yes. The passive external scan is free, with up to 5 scans per month. Detect at $15/month adds unlimited scans and deep active vulnerability testing on domains you verify, and a single deep scan is available for $19.99.
What does the scan check?
The passive scan observes your public surface across five areas: TLS/SSL posture (protocol, cipher strength, certificate validity, HSTS), HTTP security headers, exposed services and open ports, information disclosure such as version banners, and MCP / AI exposure — publicly reachable Model Context Protocol endpoints and whether they enforce authentication. The Detect deep scan adds active testing for CVEs, exposed paths, misconfigurations, and unauthenticated MCP tool-catalog disclosure on domains you have verified ownership of.
What is the MCP / AI exposure check?
MCP (Model Context Protocol) is how AI agents connect to tools — file access, databases, internal APIs, and more. An MCP server that is reachable from the public internet without authentication is a direct route to those tools for anyone who finds it. flaw.co discovers publicly reachable MCP endpoints on your domain and reports whether they enforce authentication, use encrypted transport, and have a safe CORS posture. It runs on every scan, free, with no configuration. The deep tier additionally checks whether an endpoint will disclose its entire tool catalog to an unauthenticated caller.
Why does external MCP scanning matter?
Most AI-security tooling watches MCP activity from inside your cloud account, which means it can only see servers you already know about and have instrumented. It cannot see a server a team spun up and accidentally left public. flaw.co takes the attacker’s view: it scans from the outside with nothing but your domain, so it catches exposed MCP endpoints precisely because they are reachable from the public internet — the same way an attacker would find them.
Do I need to verify my domain?
The free passive scan works on any domain, since it only observes what is publicly reachable. Deep active testing requires proof of domain ownership via a DNS TXT record or a well-known file, so active probes only ever run against domains you control.
How is the grade calculated?
Each scan produces a letter grade (A–F) and a 0–100 score, weighted across the five check families. Findings are only the checks that did not pass — the report shows how many checks ran alongside how many need attention, so the grade reflects your real external posture.
Can flaw.co monitor my domains automatically?
Yes, on Detect. Any domain you have scanned can be put on an automatic rescan — weekly, biweekly, monthly, quarterly, or semiannual. We only email you when something actually changes: a new finding, a resolved one, or a grade that moved. A rescan that finds nothing new sends nothing at all, so the arrival of an email always means something worth reading.
Is the scan intrusive or safe to run?
The passive scan is non-intrusive by design: it opens normal connections and reads what your servers publicly volunteer, sending no payloads and exercising no endpoints. The deep tier performs active testing but only on domains you have verified, and excludes aggressive techniques like fuzzing and brute-force.