[•]Detect

See what an attacker sees.

Outside-in scanning for your live domains, applications, infrastructure, and MCP / AI endpoints. No agent, no install, nothing to deploy — Detect reads what your servers already tell the public internet.

What Detect checks

Five families of checks, one grade, and a fix for every finding.

Every scan examines your public surface across five areas. Nothing is guessed and nothing is invented — a finding is a check that did not pass, and every one names the specific control to change and the PCI DSS v4.0.1 requirement it maps to, where an honest mapping exists.

TLS & certificates

Protocol versions, cipher strength, certificate validity and expiry, HSTS. The layer everything else on your surface depends on.

Security headers

Content-Security-Policy, frame options, transport security, and the rest of the header set browsers use to defend your users on your behalf.

Exposed surface

Open ports and reachable services. What you have facing the internet is often more than what you meant to have facing the internet.

Information disclosure

Version banners, server fingerprints, and the small volunteered details that tell an attacker exactly which exploit to reach for.

MCP / AI exposure

Publicly reachable Model Context Protocol endpoints and whether they enforce authentication, encrypt transport, and keep a safe CORS posture — the surface AI agents open that nothing else scans for.

Passive

Non-intrusive by design. It opens normal connections and reads what your servers publicly volunteer. No payloads are sent, no endpoints are exercised. Free on any domain, right now, without asking anyone.

Deep

Active testing for CVEs, exposed paths, misconfigurations, and unauthenticated MCP tool-catalog disclosure — and it runs only on domains you have proven you control. Ownership is verified before a single active probe is sent, enforced in the scan worker itself, not just the UI.

How it scores

A letter grade you can act on, and monitoring that only speaks up when something changes.

Each scan produces a letter grade (A–F) and a 0–100 score, weighted across the five check families. The report shows how many checks ran alongside how many need attention, so the grade reflects your real external posture — not a guess dressed up as one.

On Pro, any scanned domain can be put on an automatic rescan — weekly, biweekly, monthly, quarterly, or semiannual. We only email when something actually changes: a new finding, a resolved one, or a grade that moved. A rescan that finds nothing new sends nothing at all, so an email always means something worth reading.

5
Check families, every scan
A–F
Letter grade, 0–100 score
Change-only alerts on Pro — a new finding, a resolved one, or a grade that moved. Silence otherwise.
Pricing

Start free. Go deep when you need to.

The full passive scan is free on every plan — up to 5 scans a month, all five check families, a real letter grade. Pro adds unlimited scans, active deep testing on verified domains, scheduled rescans, and change-only monitoring.

Free — $0

Full passive scan, up to 5/month. All five families, letter grade, PCI DSS mapping.

Pro — $19.99/mo

$15.99/mo billed annually. Unlimited scans, deep active testing on verified domains, scheduled rescans, change-only alerts.

Single Deep Scan — $29.99

One-time active deep scan for a single verified domain. No subscription required.

Full details and the Detect + Code bundle are on the pricing page.

Detect covers what's deployed. Code covers what's shipping.
Add automated security review on every pull request — bundle both for $24/mo.
flaw.co
Passive external scan · no intrusive testing performed