External security scan

See where your perimeter would fail a review.

A free, passive external scan across TLS, headers, exposed services, information disclosure, and MCP / AI exposure. No intrusive testing — we observe only what is publicly reachable.

Enter a domain — every scan includes MCP / AI exposure alongside TLS, headers, exposed services, and disclosure.
Free — no account required
We scan only what is publicly reachable. A flaw.co security service by Paying.co.

Built by a payments security team

Domains scanned
Scans run
Findings surfaced
131+
EMV L3 certifications delivered

Scan counts update live. Certification record is Paying.co's, across US, Canada, Europe, LATAM and the Caribbean.

What your report looks like

Open the full example scan →

Every scan returns a grade, a score for each of the five families, and findings written out in full — what we detected, why it matters, how to fix it, and the PCI DSS requirement it maps to. This is a real report, not a summary of one.

Surface exposure
100/100
TLS / SSL
96/100
Disclosure
100/100
HTTP headers
76/100
MCP / AI exposure
100/100
low
HSTS not enforced on TLS endpoint
tls_no_hstshsts
What we detected

The TLS endpoint did not return a Strict-Transport-Security header.

Why it matters

Without HSTS a browser will attempt the first connection over plaintext, leaving that request open to downgrade and interception before the redirect to HTTPS ever happens.

How to fix it

Set Strict-Transport-Security with a max-age of at least 180 days at the CDN or reverse proxy so it covers every response.

PCI DSS

4.2.16.4.3

info
Multiple security headers absent across the response
headers_broadly_absentmaturity-signal
What we detected

6 of 6 baseline security headers were not present.

Why it matters

Most standard security headers are missing at once. Individually minor, together this reads as no active security owner — the strongest signal that deeper gaps exist and that no one is maintaining the edge.

How to fix it

Adopt a baseline header set (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy) at the CDN or reverse proxy so every response is covered by default.

PCI DSS

6.4.32.2.1

More findings in the full report. Run a scan without an account to see your grade, every family score, and a sample finding in full. Sign in free to open the rest.

Scan your domain →
New

Now scanning for exposed MCP & AI endpoints

AI agents connect to the world through MCP (Model Context Protocol) servers — the endpoints that expose an agent's tools: file access, database queries, internal APIs. An MCP server left reachable and unauthenticated is a direct path to those tools. Runtime platforms only see this from inside your cloud. flaw.co finds it from the outside, the way an attacker would, with nothing but your domain.

Discovery

Probes your public surface for reachable MCP endpoints across common paths and subdomains.

Auth posture

Confirms whether each endpoint enforces authentication — or answers anyone who asks.

Tool disclosure

Deep scans catch endpoints that hand over their entire tool catalog with no credentials.

Included in every scan, free. No configuration — run a scan and the MCP / AI exposure check runs alongside TLS, headers, surface, and disclosure.

Frequently asked questions

Is flaw.co free?
Yes. The passive external scan is free, with up to 5 scans per month. A Pro plan at $19.99/month adds unlimited scans and deep active vulnerability testing on domains you verify, and a single deep scan is available for $29.99.
What does the scan check?
The passive scan observes your public surface across five areas: TLS/SSL posture (protocol, cipher strength, certificate validity, HSTS), HTTP security headers, exposed services and open ports, information disclosure such as version banners, and MCP / AI exposure — publicly reachable Model Context Protocol endpoints and whether they enforce authentication. The Pro deep scan adds active testing for CVEs, exposed paths, misconfigurations, and unauthenticated MCP tool-catalog disclosure on domains you have verified ownership of.
What is the MCP / AI exposure check?
MCP (Model Context Protocol) is how AI agents connect to tools — file access, databases, internal APIs, and more. An MCP server that is reachable from the public internet without authentication is a direct route to those tools for anyone who finds it. flaw.co discovers publicly reachable MCP endpoints on your domain and reports whether they enforce authentication, use encrypted transport, and have a safe CORS posture. It runs on every scan, free, with no configuration. The deep tier additionally checks whether an endpoint will disclose its entire tool catalog to an unauthenticated caller.
Why does external MCP scanning matter?
Most AI-security tooling watches MCP activity from inside your cloud account, which means it can only see servers you already know about and have instrumented. It cannot see a server a team spun up and accidentally left public. flaw.co takes the attacker’s view: it scans from the outside with nothing but your domain, so it catches exposed MCP endpoints precisely because they are reachable from the public internet — the same way an attacker would find them.
Do I need to verify my domain?
The free passive scan works on any domain, since it only observes what is publicly reachable. Deep active testing requires proof of domain ownership via a DNS TXT record or a well-known file, so active probes only ever run against domains you control.
How is the grade calculated?
Each scan produces a letter grade (A–F) and a 0–100 score, weighted across the five check families. Findings are only the checks that did not pass — the report shows how many checks ran alongside how many need attention, so the grade reflects your real external posture.
Can flaw.co monitor my domains automatically?
Yes, on Pro. Any domain you have scanned can be put on an automatic rescan — weekly, biweekly, monthly, quarterly, or semiannual. We only email you when something actually changes: a new finding, a resolved one, or a grade that moved. A rescan that finds nothing new sends nothing at all, so the arrival of an email always means something worth reading.
Is the scan intrusive or safe to run?
The passive scan is non-intrusive by design: it opens normal connections and reads what your servers publicly volunteer, sending no payloads and exercising no endpoints. The deep tier performs active testing but only on domains you have verified, and excludes aggressive techniques like fuzzing and brute-force.