About

We look at your security the way an attacker does — inside and out.

flaw.co is built by payment engineers. Detect reads what your servers already tell the public internet; Code reviews what your team is about to ship. No agent, no install, nothing to deploy for either.

What Detect does

Five families of checks, one grade, and a fix for every finding.

Every scan examines your public surface across five areas. Nothing is guessed and nothing is invented — a finding is a check that did not pass, and every one of them names the specific control to change.

TLS & certificates

Protocol versions, cipher strength, certificate validity and expiry, HSTS. The layer everything else on your surface depends on.

Security headers

Content-Security-Policy, frame options, transport security, and the rest of the header set browsers use to defend your users on your behalf.

Exposed surface

Open ports and reachable services. What you have facing the internet is often more than what you meant to have facing the internet.

Information disclosure

Version banners, server fingerprints, and the small volunteered details that tell an attacker exactly which exploit to reach for.

MCP / AI exposure

Publicly reachable Model Context Protocol endpoints and whether they enforce authentication, encrypt transport, and keep a safe CORS posture — the surface AI agents open that nothing else scans for.

Passive

Non-intrusive by design. It opens normal connections and reads what your servers publicly volunteer. No payloads are sent, no endpoints are exercised. You can run it on any domain, right now, without asking anyone.

Deep

Active testing for CVEs, exposed paths, and misconfigurations — and it runs only on domains you have proven you control. Ownership is verified before a single active probe is sent. That is not a setting; it is enforced in the scan worker itself.

Findings are mapped to PCI DSS v4.0.1 requirements where an honest mapping exists — and left unmapped where it does not. A fabricated citation in front of a technical buyer is worse than no citation at all.

What Code does

Security-scoped review on every pull request.

Detect watches what's already live. Code catches what's about to ship — every pull request against a connected repo gets reviewed against four categories, scoped to what actually changed, not the whole codebase.

Secrets & credentials

API keys, tokens, and connection strings that made it into a diff before anyone noticed — the single most common way a breach starts.

Injection risks

SQL, command, and template injection patterns introduced by new or changed code paths, flagged with the specific line and why it's exploitable.

Auth & session changes

Modifications to authentication, authorization, or session handling get closer scrutiny — this is where a one-line change quietly becomes a privilege escalation bug.

Dependency CVEs

New or updated packages checked against known vulnerabilities before they land in your default branch.

Findings post as inline PR comments — no separate dashboard to remember to check. Install via the GitHub App, pick which repos get reviewed, and every pull request against them is covered from that point on.

Who we are

flaw.co is built by Paying.co.

Paying.co is a payment engineering firm. We do EMV Level 3 certification, custom Android payment applications, SoftPOS, unattended payment systems, and PCI and security compliance work — across the US, Canada, Europe, LATAM, and the Caribbean.

We built flaw.co because we kept finding the same things. Expired certificates on payment pages. TLS 1.0 still enabled on a terminal management endpoint. A version banner on a host that had no business being reachable at all. These are not exotic failures. They are the ordinary ones, and they are everywhere, and almost nobody is looking.

130+
EMV L3 certifications completed
5
Regions served
Processor experience across Global Payments, TSYS, Fiserv, Worldpay, Elavon, Moneris, and Datacap

That is the difference between these tools and generic ones. We are not a security vendor that discovered payments. We are payment engineers who got tired of what we were seeing — in what was already deployed, and in what was about to be.

After the finding

A report is not a fix. A comment is not a fix either.

flaw.co will tell you what is wrong, what it means, and what to change — a report from Detect, an inline comment from Code. Every finding carries a concrete remediation — the header to set, the protocol to disable, the line to change. For a great many teams, that is enough. Take it, hand it to your engineers, and it is done by Friday.

Sometimes it is not enough. The finding sits inside a payment terminal fleet you did not build. The fix touches a certification you cannot afford to invalidate. The vulnerable code path belongs to a processor integration nobody on your team has opened in three years.

That is the work Paying.co does. The same engineers who wrote the checks can do the remediation, and we can do it without breaking the certification underneath it — because we do that certification too.

Have a report and need it handled?
Talk to the engineers who built the scanner.
Book a meeting →

Detect's report is a security readiness signal, not a compliance attestation — it does not certify PCI DSS compliance. Formal certification is a separate engagement, one Paying.co can also run.

flaw.co
Security, inside and out